Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
What is the nature of the spoofing? An authenticated attacker could cause an affected Exchange server to send HTTP requests to internal or loopback systems by submitting a specially crafted internet calendar subscription. Successful exploitation could expose sensitive information returned as valid calendar content from resources reachable by the server. According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The attacker must be authenticated using valid Exchange user credentials.
<a href="https://www.linkedin.com/in/navaponpremkasem/">71C4</a>