CVE-2018-8581
Microsoft Exchange Server Privilege Escalation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
YesDecision
Descriptions
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.
Existe una vulnerabilidad de elevaciĆ³n de privilegios en Microsoft Exchange Server. Esto tambiĆ©n se conoce como "Microsoft Exchange Server Elevation of Privilege Vulnerability". Esto afecta a Microsoft Exchange Server.
This vulnerability allows remote attackers to impersonate arbitrary users on vulnerable installations of Microsoft Exchange Server. Authentication is required to exploit this vulnerability.
The specific flaw exists within the use of NTLM authentication in Exchange Server. NTLM responses produced by the server can be reflected back to the server to authenticate arbitrary EWS requests. An attacker can leverage this vulnerability to disclose and modify the data of any user of the Exchange server.
A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-03-14 CVE Reserved
- 2018-11-14 CVE Published
- 2018-12-27 First Exploit
- 2022-03-03 Exploited in Wild
- 2022-03-17 KEV Due Date
- 2024-08-05 CVE Updated
- 2024-08-29 EPSS Updated
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/105837 | Third Party Advisory | |
http://www.securitytracker.com/id/1042141 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/WyAtu/CVE-2018-8581 | 2018-12-30 | |
https://github.com/qiantu88/CVE-2018-8581 | 2018-12-27 |
URL | Date | SRC |
---|---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8581 | 2020-04-09 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2010 Search vendor "Microsoft" for product "Exchange Server" and version "2010" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2013 Search vendor "Microsoft" for product "Exchange Server" and version "2013" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2016 Search vendor "Microsoft" for product "Exchange Server" and version "2016" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2019 Search vendor "Microsoft" for product "Exchange Server" and version "2019" | - |
Affected
|