A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8151.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Microsoft Exchange | — | Download and install Microsoft KB4092041 | Aug 10, 2023 | May 9, 2018 |
| Msft | — | Security Update For Exchange Server 2013 SP1 (KB4092041)Security Update For Exchange Server 2013 CU20 (KB4092041)Update Rollup 21 for Exchange Server 2010 Service Pack 3 (KB4091243)Security Update For Exchange Server 2013 CU19 (KB4092041)Update Rollup 24 for Exchange Server 2010 Service Pack 3 (KB4458321) | May 8, 2018 | May 8, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub