CVE-2019-1136Microsoft Exchange Server vulnerability

4 documents4 sources
Severity
8.1HIGHNVD
EPSS
5.4%
top 9.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateMay 24

Description

An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages4 packages

NVDmicrosoft/exchange_server2010, 2013+1
CVEListV5microsoft/microsoft_exchange_server2010 Service Pack 3
CVEListV5microsoft/microsoft_exchange_server_2013Cumulative Update 23
CVEListV5microsoft/microsoft_exchange_server_2016Cumulative Update 12, Cumulative Update 13+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2pcm-v58v-gmvq: An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'2022-05-24
CVEList
CVE-2019-1136: An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'2019-07-29

📋Vendor Advisories

1
Microsoft
Microsoft Exchange Server Elevation of Privilege Vulnerability2019-07-09
CVE-2019-1136 — Microsoft Exchange Server vulnerability | cvebase