CVE-2018-8448

Severity
5.4MEDIUM
EPSS
1.8%
top 17.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 10
Latest updateMay 13

Description

An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages2 packages

NVDmicrosoft/exchange_server2013, 2016+1
CVEListV5microsoft/microsoft_exchange_server2013 Cumulative Update 21, 2016 Cumulative Update 10+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-ghxr-557p-73pc: An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft2022-05-13
CVEList
CVE-2018-8448: An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft2018-10-10

📋Vendor Advisories

1
Microsoft
Microsoft Exchange Server Elevation of Privilege Vulnerability2018-10-09
CVE-2018-8448 (MEDIUM CVSS 5.4) | An elevation of privilege vulnerabi | cvebase.io