Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2019-0724

7 documents6 sources
Severity
8.1HIGH
EPSS
61.4%
top 1.68%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMar 5
Latest updateMay 13

Description

An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0686.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages5 packages

CVEListV5microsoft/microsoft_exchange_server_2019Cumulative Update 1
NVDmicrosoft/exchange_server4 versions+3
CVEListV5microsoft/microsoft_exchange_server_2010Service Pack 3 Update Rollup 26
CVEListV5microsoft/microsoft_exchange_server_2013Cumulative Update 22
CVEListV5microsoft/microsoft_exchange_server_2016Cumulative Update 12

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r53v-h866-83xq: An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'2022-05-13
CVEList
CVE-2019-0724: An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'2019-03-06

💥Exploits & PoCs

1
Metasploit
Microsoft Exchange Privilege Escalation Exploit

📋Vendor Advisories

1
Microsoft
Microsoft Exchange Server Elevation of Privilege Vulnerability2019-02-12

🕵️Threat Intelligence

1
Tenable
Proof-of-Concept Code Gives Standard Microsoft Exchange Users Domain Administrator Privileges (CVE-2019-0724, CVE-2019-0686)2019-01-22
CVE-2019-0724 (HIGH CVSS 8.1) | An elevation of privilege vulnerabi | cvebase.io