Exchange Error Message Cross Site Scripting Vulnerabilities
29 Jul. 2015
Summary
Cross-site scripting (XSS) vulnerability in errorfe.aspx in Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to inject arbitrary web script or HTML via the msgParam parameter in an authError action, aka "Exchange Error Message Cross Site Scripting Vulnerability."
Vulnerable Systems:
* Microsoft Exchange Server 2013 SP1 and Cumulative
Microsoft Word is prone to a Cross-site scripting vulnerability. Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial-of-service conditions.