CVE-2018-8153
published 2018-05-09CVE-2018-8153: A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange…
PriorityP428medium5.4CVSS 3.0
AVNACLPRNUIRSUCLILAN
EPSS
3.48%
87.8th percentile
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Spoofing Vulnerability." This affects Microsoft Exchange Server.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | microsoft_exchange_server | — | — |
| microsoft | microsoft_exchange_server | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_8 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_9 | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_msrc5.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Exchange Spoofing Vulnerability
vendor_msrc·2018-05-08·CVSS 5.4
CVE-2018-8153 [MEDIUM] Microsoft Exchange Spoofing Vulnerability
Microsoft Exchange Spoofing Vulnerability
Description: A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests. An attacker who successfully exploited the vulnerability could perform script or content injection attacks, and attempt to trick the user into disclosing sensitive information. An attacker could also redirect the user to a malicious website that could spoof content or the vulnerability could be used as a pivot to chain an attack with other vulnerabilities in web services.
To exploit the vulnerability, an attacker could send a specially crafted email containing a malicious link to a user. An attacker could also use a chat client to social engineer a user into clicking the malicious link. However, in both exampl
GHSA
GHSA-w3vw-mgpx-6mjp: A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Excha
ghsa_unreviewed·2022-05-13
CVE-2018-8153 [MEDIUM] CWE-290 GHSA-w3vw-mgpx-6mjp: A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Excha
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Spoofing Vulnerability." This affects Microsoft Exchange Server.
No detection rules found.
No public exploits indexed.
Qualys
May 2018 Patch Tuesday – Medium Weight, However One Active Exploit Needs Attention
blogs_qualys·2018-05-08·CVSS 7.6
[HIGH] May 2018 Patch Tuesday – Medium Weight, However One Active Exploit Needs Attention
This May’s Patch Tuesday has quite a few Microsoft fixes for both the OS and browsers. In all, 67 unique CVEs are addressed in 17 KB articles, with 21 CVEs marked Critical. 32 of these CVEs reference Remote Code Execution, 19 of which are Critical. Those who use Hyper-V have some updates to pay attention to as well.
## OS, Browser and Office
In terms of prioritization, we recommend patching user-facing assets first, with a focus on OS, browser patches, and Office to resolve scripting engine vulnerabilities.
We recommend you first test and deploy the fixes for CVE-2018-8174 , which addresses how the scripting engine handles memory objects. It should be noted that Microsoft lists this patch as Exploitation Detected, so this update should get immediate attention.
Usually browsers are targ
Qualys
May 2018 Patch Tuesday - Medium Weight, However One Active Exploit Needs Attention | Qualys
blogs_qualys·2018-05-08·CVSS 7.6
[HIGH] May 2018 Patch Tuesday - Medium Weight, However One Active Exploit Needs Attention | Qualys
This May’s Patch Tuesday has quite a few Microsoft fixes for both the OS and browsers. In all, 67 unique CVEs are addressed in 17 KB articles, with 21 CVEs marked Critical. 32 of these CVEs reference Remote Code Execution, 19 of which are Critical. Those who use Hyper-V have some updates to pay attention to as well.
### OS, Browser and Office
In terms of prioritization, we recommend patching user-facing assets first, with a focus on OS, browser patches, and Office to resolve scripting engine vulnerabilities.
We recommend you first test and deploy the fixes for CVE-2018-8174, which addresses how the scripting engine handles memory objects. It should be noted that Microsoft lists this patch as Exploitation Detected, so this update should get immediate attention.
Usually browsers are targ
http://www.securityfocus.com/bid/104045http://www.securitytracker.com/id/1040850https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8153http://www.securityfocus.com/bid/104045http://www.securitytracker.com/id/1040850https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8153
2018-05-09
Published