CVE-2017-8621 describes an open redirect vulnerability in Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3/CU16, and Exchange Server 2016 CU5. This medium-severity flaw (CVSS 6.1) allows an attacker to redirect users to malicious sites, potentially leading to spoofing and information disclosure. The attack requires user interaction (UI:R) and has low impact on confidentiality and integrity. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) is reported, it has garnered some community discussion and media coverage, indicating awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2010:sp3:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_16:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2013:sp1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_5:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.