Executive brief
An elevation of privilege vulnerability in Microsoft Exchange Server allows a remote attacker to impersonate other users. The flaw stems from insufficient permission validation, potentially granting the attacker the same privileges as the impersonated user.
Affected products
- Microsoft Exchange Server 2010, 2013, 2016, 2019
Timeline
- 2018-11-13: disclosed: NVD Published Date
- 2018-11-14: patched: Microsoft released security guidance and patches.
- 2022-03-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
- 2022-03-03: exploited: Reported as exploited in the wild.