CVE-2018-8448

MEDIUM

Description

An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.

References

http://www.securityfocus.com/bid/105492

http://www.securitytracker.com/id/1041836

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8448

Details

Source: MITRE

Published: 2018-10-10

Updated: 2018-11-27

Type: CWE-264

Risk Information

CVSS v2.0

Base Score: 5.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Impact Score: 4.9

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3.0

Base Score: 5.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Impact Score: 2.5

Exploitability Score: 2.8

Severity: MEDIUM