CVE-2018-8374
published 2018-08-15CVE-2018-8374: A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulnerability."…
PriorityP424medium4.3CVSS 3.0
AVNACLPRLUINSUCNILAN
EPSS
3.02%
85.9th percentile
A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulnerability." This affects Microsoft Exchange Server.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | microsoft_exchange_server | — | — |
| microsoft | microsoft_exchange_server | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_10 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_9 | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_msrc4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g5px-7wp3-wmcp: A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulner
ghsa_unreviewed·2022-05-13
CVE-2018-8374 [MEDIUM] GHSA-g5px-7wp3-wmcp: A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulner
A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulnerability." This affects Microsoft Exchange Server.
Microsoft
Microsoft Exchange Server Tampering Vulnerability
vendor_msrc·2018-08-14·CVSS 4.3
CVE-2018-8374 [MEDIUM] Microsoft Exchange Server Tampering Vulnerability
Microsoft Exchange Server Tampering Vulnerability
Description: A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data.
To exploit the vulnerability, an attacker would need to be authenticated on an affected Exchange Server. The attacker would then need to send a specially modified request to the server, targeting a specific user.
The security update addresses the vulnerability by modifying how Microsoft Exchange Server handles profile data.
Microsoft Exchange Server: Microsoft Exchange Server
Impact: Tampering
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely;Older Software Release:Exploitati
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/104993http://www.securitytracker.com/id/1041481https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8374http://www.securityfocus.com/bid/104993http://www.securitytracker.com/id/1041481https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8374
2018-08-15
Published