Jul 2019:
CVE-2019-1137 Published on July 15, 2019
A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.
Products Associated with CVE-2019-1137
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Exchange Server 2016:- Version Cumulative Update 12 is affected.
- Version Cumulative Update 13 is affected.
- Version Cumulative Update 1 is affected.
- Version Cumulative Update 2 is affected.
- Version Cumulative Update 23 is affected.
Exploit Probability
EPSS
0.67%
Percentile
71.06%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.