Jul 2019:
CVE-2019-1137 Published on July 15, 2019

A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.

NVD


Products Associated with CVE-2019-1137

Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.

 
 
 

Affected Versions

Microsoft Exchange Server 2016: Microsoft Exchange Server 2019: Microsoft Exchange Server 2013:

Exploit Probability

EPSS
0.67%
Percentile
71.06%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.