106906vdb entry
http://www.securityfocus.com/bid/106906 CVE-2019-0724
HIGH
Microsoft Exchange Privilege Escalation Exploit
Record summary
CVE-2019-0724 has a selected CVSS score of 8.1 (high); EIP currently links 1 catalogued exploit.
Description
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0686.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
Microsoft Exchange Server 2010Browse Microsoft / Microsoft Exchange Server 2010 | CVE List | Service Pack 3 Update Rollup 26 | affected |
Microsoft Exchange Server 2013Browse Microsoft / Microsoft Exchange Server 2013 | CVE List | Cumulative Update 22 | affected |
Microsoft Exchange Server 2016Browse Microsoft / Microsoft Exchange Server 2016 | CVE List | Cumulative Update 12 | affected |
Microsoft Exchange Server 2019Browse Microsoft / Microsoft Exchange Server 2019 | CVE List | Cumulative Update 1 | affected |
Proofs of concept
1Catalogued exploits
MetasploitMicrosoft Exchange Privilege Escalation ExploitMetasploit auxiliary PoCby Petros Koutroumpis +1 moreNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-0724 portal.msrc.microsoft.comConfirmation
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0724