CVE-2018-8154
Summary
| CVE | CVE-2018-8154 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-09 19:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8151. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Exchange Server | 2010 | sp3 | All | All |
| Application | Microsoft | Exchange Server | 2013 | cumulative_update_19 | All | All |
| Application | Microsoft | Exchange Server | 2013 | cumulative_update_20 | All | All |
| Application | Microsoft | Exchange Server | 2013 | sp1 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_8 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_9 | All | All |
| Application | Microsoft | Exchange Server | 2010 | sp3 | All | All |
| Application | Microsoft | Exchange Server | 2013 | cumulative_update_19 | All | All |
| Application | Microsoft | Exchange Server | 2013 | cumulative_update_20 | All | All |
| Application | Microsoft | Exchange Server | 2013 | sp1 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_8 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_9 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Exchange Server CVE-2018-8154 Remote Code Execution Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8154 | CONFIRM | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| Microsoft Exchange Server Multiple Flaws Let Remote Users Spoof Content, Inject Scripting Code, Obtain Potentially Sensitive Information, and Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.