CVE-2017-11932: Microsoft Exchange Server

High severity, CVSS 8.1. EPSS: 5.9% chance of exploitation in the next 30 days.

Microsoft Exchange Server 2016 CU5 and Microsoft Exchange Server 2016 CU5 allow a spoofing vulnerability due to the way Outlook Web Access (OWA) validates web requests, aka "Microsoft Exchange Spoofing Vulnerability".

Affected products

Published 2017-12-12. Last modified 2026-06-17.