CVE-2017-11932: Microsoft Exchange Server
High severity, CVSS 8.1. EPSS: 5.9% chance of exploitation in the next 30 days.
Microsoft Exchange Server 2016 CU5 and Microsoft Exchange Server 2016 CU5 allow a spoofing vulnerability due to the way Outlook Web Access (OWA) validates web requests, aka "Microsoft Exchange Spoofing Vulnerability".
Affected products
- Microsoft Exchange Server: version 2016 only
Published 2017-12-12. Last modified 2026-06-17.