This host is missing an important security update according to Microsoft Bulletin MS14-075.
Successful exploitation will allow remote attackers to conduct spoofing and cross-site scripting attacks. Impact Level: System/Application
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the given link, https://technet.microsoft.com/library/security/MS14-075
Multiple flaws are due to, - An error when validating a request token. - Certain unspecified input is not properly sanitised before being returned to the user. - Certain input related to redirection tokens is not properly verified before being used to redirect users.
Microsoft Exchange Server 2007 Service Pack 3 and prior Microsoft Exchange Server 2010 Service Pack 3 and prior Microsoft Exchange Server 2013 Service Pack 1 and prior Microsoft Exchange Server 2013 Cumulative Update 6.
Get the vulnerable file version and check appropriate patch is applied or not.
CVE CVE-2014-6319, CVE-2014-6325, CVE-2014-6326, CVE-2014-6336
CVSS Base Score: 5.0
- Microsoft AntiXSS Library Information Disclosure Vulnerability (2607664)
- Microsoft Windows Active Directory Denial of Service Vulnerability (2830914)
- Microsoft Windows SAMR Protocol Security Bypass Vulnerability (2934418)
- Microsoft IIS Malformed File Extension Denial of Service Vulnerability
- Microsoft Windows Digital Signatures Denial of Service Vulnerability (2868626)