CVE-2018-8152

Severity
5.4MEDIUM
EPSS
2.4%
top 15.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 9
Latest updateMay 13

Description

An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages2 packages

CVEListV5microsoft/microsoft_exchange_server2016 Cumulative Update 8, 2016 Cumulative Update 9+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pq9h-wc5w-r94q: An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft2022-05-13
CVEList
CVE-2018-8152: An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft2018-05-09

📋Vendor Advisories

1
Microsoft
Microsoft Exchange Server Elevation of Privilege Vulnerability2018-05-08
CVE-2018-8152 (MEDIUM CVSS 5.4) | An elevation of privilege vulnerabi | cvebase.io