Medium severity6.1NVD Advisory· Published Sep 11, 2019· Updated Jun 17, 2026
CVE-2019-1266
CVE-2019-1266
Description
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'.
Affected products
7cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_12:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_12:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_13:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_2:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: Cumulative Update 12
- (no CPE)range: Cumulative Update 1
Patches
Vulnerability mechanics
References
1- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1266nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.