MS15-064: Vulnerabilities in Exchange Server could allow elevation of privilege: June 9, 2015

INTRODUCTION

Microsoft has released security bulletin MS15-064. To learn more about this security bulletin:

How to obtain help and support for this security update

Help installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help protect your Windows-based computer from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support

More Information

How to obtain and install the update

Method 1: Microsoft Update

This update is available from Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see Get security updates automatically.

Method 2: Microsoft Download Center

You can also obtain the stand-alone update package through the Microsoft Download Center. Then, follow the installation instructions on the download page to install the update.

Issues that are fixed in this security update

This security update fixes the following issues that occur in an environment that is running Exchange Server 2013 Service Pack 1 (SP1) or a later update installed:
  • An information disclosure vulnerability exists in Exchange web applications when Exchange does not correctly manage same-origin policy. This security update addresses the vulnerability by changing how Exchange web applications manage same-origin policy in Exchange Server 2013 SP1 and Cumulative Update 8.
  • An elevation of privilege vulnerability exists in Exchange web applications when Exchange does not correctly manage user sessions. This security update addresses the vulnerability by changing how Exchange web applications manage user session authentication in Exchange Server 2013 SP1 and Cumulative Update 8.
  • An information-disclosure vulnerability exists in Exchange web applications when Exchange does not correctly sanitize HTML strings. This security update addresses the vulnerability by correcting how Exchange web applications sanitize HTML strings in Exchange Server 2013 Cumulative Update 8.

Security update deployment information

Microsoft Exchange Server 2013
File hash information
File information
Properties

Article ID: 3062157 - Last Review: Jun 9, 2015 - Revision: 1

Feedback