Junglewise Threat Intelligence

CVE-2018-8581: Microsoft Exchange Server Privilege Escalation Vulnerability

CVE-2018-8581 · Severity: critical · CVSS 7.4 · Exploited in the wild · Published 2022-03-03

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

An elevation of privilege vulnerability in Microsoft Exchange Server allows a remote attacker to impersonate other users. The flaw stems from insufficient permission validation, potentially granting the attacker the same privileges as the impersonated user.

Affected products

  • Microsoft Exchange Server 2010, 2013, 2016, 2019

Timeline

  • 2018-11-13: disclosed: NVD Published Date
  • 2018-11-14: patched: Microsoft released security guidance and patches.
  • 2022-03-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
  • 2022-03-03: exploited: Reported as exploited in the wild.

Related threats