CVE-2018-8159High
Microsoft Exchange Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests. An attacker who successfully exploited this vulnerability could perform script/content injection attacks and attempt to trick the user into disclosing sensitive information. To exploit the vulnerability, an attacker could send a specially crafted email message containing a specific malicious script. The user would have to apply a highlight to the script for it to be activated. The security update addresses the vulnerability by correcting how Microsoft Exchange validates web requests.
🎯 Affected products4
- Microsoft Exchange Server 2013 Cumulative Update 19
- Microsoft Exchange Server 2013 Cumulative Update 20
- Microsoft Exchange Server 2016 Cumulative Update 8
- Microsoft Exchange Server 2016 Cumulative Update 9
✅ Remediation
KB4092041 (Security Update)
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2018-8159
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=909e04bb-5ae5-498d-9c9b-545f78a20aeb
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=2b2cf7bd-a14b-4513-8aaa-e7d1beef9482
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=d39c23d1-8e6b-4e25-8e05-5d8487b0194f
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=59e87632-8ac1-4a70-85eb-dd8cc3d54066