انتقل إلى المحتوى الرئيسي
English
logo
مستوى الخطورة: عالية
ثغرة

الرقم المرجعي: NCSC-TAD-2606-001CVSS 0

Microsoft Exchange Server XSS Vulnerability

نوع التهديد:
غير متوفر
مستوى المشاركة (TLP):
CLEAR
CVE:
CVE-2026-42897

نظرة عامة

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

التقنيات المتأثرة

  • Microsoft Exchange Outlook Web Access (OWA)

إجراءات الحد من المخاطر والإجراءات الفورية

  1. 01

    Apply the latest Exchange Server security updates and maintain existing mitigations as an additional layer of defence.

  2. 02

    Exchange Emergency Mitigation (EM) Service: Block mitigation M2 from re-applying and remove the M2 IIS rules.

  3. 03

    EOMT script: Roll back the mitigation.

المراجع