CVE-2018-8581

HIGH KEV RANSOMWARE

Microsoft Exchange Server - Privilege Escalation

Title source: llm

Description

An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.

Exploits (6)

nomisec WORKING POC 375 stars
by Ridter · remote
https://github.com/Ridter/Exchange2domain
nomisec WORKING POC 332 stars
by WyAtu · remote
https://github.com/WyAtu/CVE-2018-8581
nomisec WORKING POC 5 stars
by qiantu88 · remote-auth
https://github.com/qiantu88/CVE-2018-8581
patchapalooza WORKING POC
by mirrors_WyAtu · poc
https://gitee.com/mirrors_WyAtu/CVE-2018-8581
patchapalooza WORKING POC
by thezdi · remote
https://github.com/thezdi/PoC

Scores

CVSS v3 7.4
EPSS 0.9150
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CISA KEV 2022-03-03
VulnCheck KEV 2022-03-03
InTheWild.io 2022-03-03
ENISA EUVD EUVD-2018-20198
Ransomware Use Confirmed
Status published
Products (4)
microsoft/exchange_server 2010
microsoft/exchange_server 2013
microsoft/exchange_server 2016
microsoft/exchange_server 2019
Published Nov 14, 2018
KEV Added Mar 03, 2022
Tracked Since Feb 18, 2026