CVE-2019-0686

6 documents5 sources
Severity
7.4HIGH
EPSS
10.9%
top 6.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 5
Latest updateMay 13

Description

An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0724.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2

Affected Packages5 packages

CVEListV5microsoft/microsoft_exchange_server_2019Cumulative Update 1
NVDmicrosoft/exchange_server4 versions+3
CVEListV5microsoft/microsoft_exchange_server_2010Service Pack 3 Update Rollup 26
CVEListV5microsoft/microsoft_exchange_server_2013Cumulative Update 22
CVEListV5microsoft/microsoft_exchange_server_2016Cumulative Update 12

Patches

🔴Vulnerability Details

2
GHSA
GHSA-95f3-h5c9-7w6c: An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'2022-05-13
CVEList
CVE-2019-0686: An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'2019-03-06

📋Vendor Advisories

1
Microsoft
Microsoft Exchange Server Elevation of Privilege Vulnerability2019-02-12

🕵️Threat Intelligence

1
Tenable
Proof-of-Concept Code Gives Standard Microsoft Exchange Users Domain Administrator Privileges (CVE-2019-0724, CVE-2019-0686)2019-01-22
CVE-2019-0686 (HIGH CVSS 7.4) | An elevation of privilege vulnerabi | cvebase.io