CVE-2019-0817 is a medium-severity spoofing vulnerability affecting Microsoft Exchange Server, specifically within its Outlook Web Access (OWA) component. The vulnerability arises from OWA's improper handling of web requests, allowing an attacker to spoof content. This client-side vulnerability requires user interaction (UI:R) and could lead to low impact on confidentiality and integrity (C:L, I:L), with no impact on availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, it was addressed in Microsoft's April 2019 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2010:sp3:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_22:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_11:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_12:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2019:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.