CVE-2018-8581

Microsoft Exchange Server

Published 14 Nov 2018 · updated 17 Jun 2026 · Analyzed

7.4 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 3 Mar 2022, with a remediation deadline of 17 Mar 2022 for US federal agencies. It has been used in ransomware campaigns.

Required action: Apply updates per vendor instructions.

Description

An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.

References