About this tag
OWA, or Outlook Web Access, is the web-based email client for Microsoft Exchange Server. Discussions on WindowsForum.com cover security vulnerabilities in OWA, including information disclosure risks from specially crafted image URLs and improper handling of web requests. Older advisories highlight session hijacking threats where an attacker could take over an authenticated OWA session. These threads focus on security updates and patches released by Microsoft to address such vulnerabilities, emphasizing the importance of keeping Exchange Server and OWA up to date to protect against potential exploits.
  1. News

    MS16-079 - Important: Security Update for Microsoft Exchange Server (3160339) - Version: 1.0

    Severity Rating: Important Revision Note: V1.0 (June 14, 2016): Bulletin published. Summary: This security update resolves vulnerabilites in Microsoft Exchange Server. The most severe of the vulnerabilities could allow information disclosure if an attacker sends a specially crafted image URL in...