← Back to CVE List
Vulnerability Intelligence Report
Microsoft Exchange Server Privilege Escalation Vulnerability

CVE-2018-8581

An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.4
HIGH
Exploitability:2.3
Impact Score:5.2
EPSS Probability:27.56%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
Microsoft Microsoft Exchange Server 2010 (affected), 2013 (affected), 2016 (affected), 2019 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
27.558%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2018-03-14T00:00:00
Published2018-11-14T01:00:00
Patch Date2018-11-13
Last Updated2025-10-21T23:45:47

LINK COPIED TO CLIPBOARD