Executive brief
A vulnerability in Microsoft Exchange Server, the platform used by organizations for email and calendaring, could allow an attacker to perform spoofing attacks. By tricking a user into interacting with a malicious link or page, an attacker can execute unauthorized scripts in the user's browser session. This could lead to the theft of sensitive information or unauthorized actions performed on behalf of the user within the email environment.
Technical details
Microsoft Exchange Server contains a cross-site scripting (XSS) vulnerability due to improper neutralization of input during web page generation (CWE-79). An unauthenticated attacker can exploit this by sending a specially crafted link to a user and inducing them to click it. Successful exploitation allows the attacker to execute malicious scripts in the context of the victim's browser session, potentially leading to session hijacking or the unauthorized disclosure of information. The vulnerability is rated with a CVSS 3.1 score of 6.1, reflecting a network attack vector and required user interaction.
Affected products
- Microsoft Exchange Server
Timeline
- 2026-06-09: advisory: Initial advisory published by Microsoft and NVD.