CVE-2017-11761
Last modified
CVE-2017-11761 is a vulnerability of currently unknown severity. Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in unintended Information Disclosure, aka "Microsoft Exchange Information Disclosure Vulnerability". EPSS estimates a 6.56% chance of exploitation in the next 30 days.
Description
Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in unintended Information Disclosure, aka "Microsoft Exchange Information Disclosure Vulnerability"
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Exchange Server | 2013 | Cumulative Update 16 |
| Microsoft | Exchange Server | 2016 | Cumulative Update 5 |
References
- http://www.securityfocus.com/bid/100731Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039320Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11761Patch, Vendor Advisory
- http://www.securityfocus.com/bid/100731Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039320Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11761Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-11761?
How severe is CVE-2017-11761?
How do I fix CVE-2017-11761?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-11754The WritePICONImage function in coders/xpm.c in ImageMagick …
- CVE-2017-11755The WritePICONImage function in coders/xpm.c in ImageMagick …
- CVE-2017-11756In Earcms Ear Music through 4.1 build 20170710, remote authe…
- CVE-2017-11757Heap-based buffer overflow in Actian Pervasive PSQL v12.10 a…
- CVE-2017-1176IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a …
- CVE-2017-11760uploadImage.php in ProjeQtOr before 6.3.2 allows remote auth…
- CVE-2017-11762The Microsoft Graphics Component on Microsoft Windows Server…
- CVE-2017-11763The Microsoft Graphics Component on Microsoft Windows Server…
- CVE-2017-11764Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windo…
- CVE-2017-11765The Microsoft Windows Kernel component on Microsoft Windows …
- CVE-2017-11766Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 170…
- CVE-2017-11767ChakraCore allows an attacker to gain the same user rights a…
Are you affected by CVE-2017-11761?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
