PT-2018-1477 · Microsoft · Exchange Server

Published

2018-08-14

·

Updated

2020-08-24

·

CVE-2018-8302

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server (affected versions not specified)
Description The issue is related to errors in handling objects in memory, which can be exploited by a remote attacker to execute arbitrary code with SYSTEM privileges. This can allow the attacker to install programs, view, change, or delete data, or create new accounts. Exploitation requires sending a specially crafted email to a vulnerable Exchange server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Improper Access Control

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01028
CVE-2018-8302
ZDI-18-944

Affected Products

Exchange Server