by @ElliotM87
20 Jan 2023

Another Strike on MS-Exchange Server - OWASSRF

by @ElliotM87
20 Jan 2023

Another Strike on MS-Exchange Server - OWASSRF

CVEs

8 High Severity

Apps

15.2.1258.27.Update 13
15.2.1118.39.Update 12
15.0.1104.5.Update 9
15.2.922.7.*
14.3.123.*
15.0.1497.2.*
15.01.*
15.1.2106.2.*
Update 4.*
15.0.1236.3.*

Screenshots from the blog posts

blog-posts/images/cld4688qhu81n0jp822f6ghkw.pngblog-posts/images/cld4688qhu81n0jp822f6ghkw.png

Summary

According to security researchers, the Microsoft Exchange servers are vulnerable to a novel exploitation technique called OWASSRF, which refers to the server-side request forgery related to Microsoft Outlook Web Access and Application.

Description

@ElliotM87

25 posts

An Independent security researcher, writer, OSINT journalist, and explorer. Hacking is a superpower use it wisely. Motto - "The best moments life has to offer to lie out of your comfort zone"

Total vcoins

0

Comments (0)