Description
Due to a flaw in the Autodiscover service of Exchange Server, an unauthenticated attacker can access its restricted resources and leverage this in conjunction with other vulnerabilities to execute arbitrary code.
Remediation
Upgrade to the latest version of Microsoft Exchange Server.
References
Related Vulnerabilities
Microsoft Exchange Server Server-Side Request Forgery (SSRF) vulnerability
Webmin v1.920 Unauhenticated Remote Command Execution
WordPress Plugin Groundhogg-Marketing Automation & CRM for WordPress Remote Code Execution (1.3.4)
WordPress Plugin Zingiri Web Shop 'ajax_save_name.php' Remote Code Execution (2.2.3)