cbcvebase.
CVE-2018-8581
published 2018-11-14

CVE-2018-8581: An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects…

PriorityP186high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-03-17
Exploited in the wild
EPSS
27.36%
97.8th percentile
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftmicrosoft_exchange_server
microsoftmicrosoft_exchange_server
microsoftmicrosoft_exchange_server
microsoftmicrosoft_exchange_server
msrcmicrosoft_exchange_server_2010
msrcmicrosoft_exchange_server_2010_service_pack_3
msrcmicrosoft_exchange_server_2013
msrcmicrosoft_exchange_server_2013_cumulative_update_21
msrcmicrosoft_exchange_server_2013_cumulative_update_22
msrcmicrosoft_exchange_server_2013_cumulative_update_23
msrcmicrosoft_exchange_server_2013_service_pack_1
msrcmicrosoft_exchange_server_2016
msrcmicrosoft_exchange_server_2016_cumulative_update_10
msrcmicrosoft_exchange_server_2016_cumulative_update_11
msrcmicrosoft_exchange_server_2016_cumulative_update_12
msrcmicrosoft_exchange_server_2016_cumulative_update_13
msrcmicrosoft_exchange_server_2016_cumulative_update_14
msrcmicrosoft_exchange_server_2016_cumulative_update_15
msrcmicrosoft_exchange_server_2016_cumulative_update_16
msrcmicrosoft_exchange_server_2016_cumulative_update_17
msrcmicrosoft_exchange_server_2016_cumulative_update_18

Detection & IOCsextracted from sources · hover to see the quote

registryHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\DisableLoopbackCheck
  • Detect presence of the DisableLoopbackCheck registry value under HKLM\SYSTEM\CurrentControlSet\Control\Lsa; its existence enables the CVE-2018-8581 NTLM relay attack vector against Exchange.
  • Monitor for man-in-the-middle activity forwarding NTLM authentication requests to Microsoft Exchange Server, which is the exploitation mechanism for this privilege escalation.
  • Alert on Exchange servers initiating outbound connections to workstations on arbitrary ports, which is a prerequisite behavior for NTLM relay exploitation chained with CVE-2018-8581.
  • Audit Exchange Web Services (EWS) authentication logs for unexpected or unauthenticated relay attempts, as attackers can relay credentials of users in the same network segment to EWS.
  • ·A registry value which enables NTLM authentication on the network loopback adapter is the root configuration flaw; future cumulative updates will correct this setting automatically during installation.
  • ·Enabling Extended Protection for Authentication on Exchange IIS endpoints (excluding Exchange Back End endpoints, which would break Exchange) ties NTLM authentication to a TLS connection and prevents relaying to Exchange web services.

CVSS provenance

nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vulncheck7.4HIGH
cisa7.4HIGH
vendor_msrc9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.