| Security Updates KB4509409 -- The security update addresses 3 vulnerabilities An |
| information disclosure vulnerability exists when Microsoft Exchange Server allows creation of |
| entities with Display Names having non-printable characters. An elevation of privilege |
| vulnerability when an attacker executes a man-in-the-middle attack to forward an |
| authentication request to Microsoft Exchange Server. A cross-site-scripting (XSS) |
| vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially |
| crafted web request to an affected Microsoft Exchange Server. |