Vendor security update-CVE-2018-8581
NAME
Microsoft – Exchange Server
- Platforms Affected:
Exchange Server - Risk Level:
high - CVE Type:
Privilege escalation
DESCRIPTION
CVE-2018-8581 is a privilege escalation vulnerability impacting Microsoft Exchange Server. A proof of concept (PoC) was observed publicly or in the underground. Security researchers claimed red team tools stolen during a recent breach event allegedly have the capacity to actively exploit this issue. Additionally, security researchers at the Cybersecurity and Infrastructure Security Agency (CISA) claimed the vulnerability was actively exploited in the wild.
CVSS Information:
- CVSS 2.0 SCORE: 5.8
- CVSS 3.0 SCORE: 7.4
- Exploit Disclosed in the Public:
true - Exploit Weaponised:
true - PoC Link:
hXXps://github[.]com/thezdi/PoC/blob/master/CVE-2018-8581/Exch_EWS_pushSubscribe[.]py
MITIGATION
The impacted vendor released patching information for impacted products and corresponding versions. The vendor addressed the vulnerability in a security update.
- Reference Link:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8581 - Patch Available:
available
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.