CVE-2017-8758: Microsoft Exchange Server

Medium severity, CVSS 6.1. EPSS: 3.4% chance of exploitation in the next 30 days.

Microsoft Exchange Server 2016 allows an elevation of privilege vulnerability when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability."

Affected products

Published 2017-09-13. Last modified 2026-06-17.