CVE-2018-8151High
Microsoft Exchange Memory Corruption Vulnerability
🔗 CVE IDs covered (1)
📋 Description
An information disclosure vulnerability exists when Microsoft Exchange improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the remote system. To exploit the vulnerability, an attacker would send a specially-crafted email to an affected Exchange Server. The security update addresses the vulnerability by modifying how Microsoft Exchange handles objects in memory.
🎯 Affected products6
- Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 21
- Microsoft Exchange Server 2013 Cumulative Update 19
- Microsoft Exchange Server 2013 Cumulative Update 20
- Microsoft Exchange Server 2013 Service Pack 1
- Microsoft Exchange Server 2016 Cumulative Update 8
- Microsoft Exchange Server 2016 Cumulative Update 9
✅ Remediation
KB4092041 (Security Update) KB4091243 (Security Update)
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2018-8151
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=909e04bb-5ae5-498d-9c9b-545f78a20aeb
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=2b2cf7bd-a14b-4513-8aaa-e7d1beef9482
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=faff77cb-7532-40cf-ad6d-f43b06d7373c
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=d39c23d1-8e6b-4e25-8e05-5d8487b0194f
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=59e87632-8ac1-4a70-85eb-dd8cc3d54066
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=f2c20ab1-3c99-4224-829f-cd8d8ae55031