Affected Systems
Microsoft Exchange Server (all versions with Outlook Web Access enabled). Specific patched versions not provided. Affects organizations exposing OWA to users.
Exploitation Status
Actively exploited in the wild. Microsoft confirmed exploitation prior to patch release. Attack vector targets OWA users via cross-site scripting to execute arbitrary JavaScript.
Business Impact
High-severity XSS vulnerability enables attackers to execute malicious JavaScript in authenticated OWA sessions. Potential impacts include session hijacking, credential theft, email exfiltration, and lateral movement. Organizations with internet-facing OWA are at immediate risk. CVE identifier not yet assigned at time of disclosure.
Urgency
🔴 Immediate
Recommended Actions
- Apply Microsoft Exchange Server security updates immediately via Windows Update or Microsoft Update Catalog
- Review Exchange Server logs and OWA access logs for suspicious JavaScript injection attempts or anomalous user session behavior
- Implement multi-factor authentication (MFA) for all OWA access if not already deployed to limit session hijacking impact
- Consider temporarily restricting OWA access to trusted IP ranges or VPN-only until patching is complete
- Monitor for unusual email forwarding rules, mailbox delegation changes, or data export activity in user mailboxes
