Rapid7 Vulnerability & Exploit Database

Microsoft CVE-2018-8265: Microsoft Exchange Remote Code Execution Vulnerability

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7 Labs
Back to Search

Microsoft CVE-2018-8265: Microsoft Exchange Remote Code Execution Vulnerability

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
10/09/2018
Created
03/19/2019
Added
10/09/2018
Modified
11/27/2018

Description

A remote code execution vulnerability exists in the way Microsoft Exchange software parses specially crafted email messages. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the system user. An attacker could then install programs; view, change, add, or delete data. To exploit this vulnerability, an attacker would need to send a specially crafted email to an affected Exchange server, and then convince the recipient to perform multiple actions while replying to the message. The security update addresses the vulnerability by correcting how Microsoft Exchange parses specially crafted email messages.

Solution(s)

  • msft-kb4459266-5e553c07-786b-41cb-811f-11e9a899b113

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;