CVE-2018-8581 — Microsoft Exchange Server Privilege Escalation Vulnerability
CVE-2018-8581: Microsoft Exchange Server Privilege Escalation Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Microsoft |
| Product | Exchange Server |
| Date added | 2022-03-03 |
| Due date | 2022-03-17 |
| Ransomware campaign use | Known |
Description
A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server.
Required action (CISA)
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2018-8581
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2018-8581
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog