In an Exchange Server 2013 environment, if security update 3150501 (dated June 14, 2016) is installed, HTML input tags are evaluated by a new function, and this prevents information disclosure. However, an input tag without an image such as <input type=text value=valuecontent> in the body of an email message may not be evaluated as expected and may not be displayed in Outlook Web Access.
Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.