cbcvebase.
CVE-2018-8154
published 2018-05-09

CVE-2018-8154: A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft…

PriorityP260critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
23.21%
97.5th percentile
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8151.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftmicrosoft_exchange_server
microsoftmicrosoft_exchange_server
microsoftmicrosoft_exchange_server
microsoftmicrosoft_exchange_server
microsoftmicrosoft_exchange_server
microsoftmicrosoft_exchange_server
msrcmicrosoft_exchange_server_2010_service_pack_3
msrcmicrosoft_exchange_server_2010_service_pack_3_update_rollup_21
msrcmicrosoft_exchange_server_2010_service_pack_3_update_rollup_24
msrcmicrosoft_exchange_server_2013_cumulative_update_19
msrcmicrosoft_exchange_server_2013_cumulative_update_20
msrcmicrosoft_exchange_server_2013_cumulative_update_21
msrcmicrosoft_exchange_server_2013_cumulative_update_22
msrcmicrosoft_exchange_server_2013_cumulative_update_23
msrcmicrosoft_exchange_server_2013_service_pack_1
msrcmicrosoft_exchange_server_2016_cumulative_update_10
msrcmicrosoft_exchange_server_2016_cumulative_update_11
msrcmicrosoft_exchange_server_2016_cumulative_update_12
msrcmicrosoft_exchange_server_2016_cumulative_update_13

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered by a specially crafted email sent to a vulnerable Exchange server; monitor for anomalous inbound email content targeting Exchange.
  • Successful exploitation results in code execution as SYSTEM; monitor Exchange server processes for unexpected child processes or privilege escalation to SYSTEM context.
  • Post-exploitation activity may include program installation, data modification/deletion, or new account creation on the Exchange server; monitor for these behaviors.
  • ·CVE-2018-8154 is distinct from CVE-2018-8151, which is an information disclosure vulnerability in Microsoft Exchange; do not conflate the two when building detection rules.
  • ·As of the advisory, the vulnerability had not been publicly disclosed or exploited in the wild; exploitation likelihood is rated 'Less Likely' for both latest and older software releases.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.