CVE-2015-1771: Microsoft Exchange Server

Medium severity, CVSS 6.8. EPSS: 5.8% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allows remote attackers to hijack the authentication of arbitrary users, aka "Exchange Cross-Site Request Forgery Vulnerability."

Affected products

Published 2015-06-10. Last modified 2026-06-17.