#VU11003 Information disclosure in Microsoft Exchange Server - CVE-2018-0941
Published: March 13, 2018 / Updated: March 13, 2018
Microsoft Exchange Server
Microsoft
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to the way that Microsoft Exchange Server handles importing data. A remote attacker with ability to upload a specially crafted file to Microsoft Exchange Outlook Web Access (OWA), can get access to potentially sensitive information.