CVE-2018-8581
KEV ransomwaremassPrivilege Escalation (Arbitrary User Impersonation) in Microsoft Exchange Server
CISA: Microsoft Exchange Server Privilege Escalation Vulnerability
CVE-2018-8581 is a privilege escalation vulnerability in Microsoft Exchange Server that, when successfully exploited, allows an attacker to impersonate any other user of the Exchange server. Impersonating an arbitrary user lets the attacker act as that user — reading their mailbox, sending messages as them, and, if the impersonated account is privileged or administrative, gaining elevated access to the messaging environment. Organizations running on-premises Microsoft Exchange Server are affected; the provided data does not specify the affected version ranges, so operators should consult Microsoft's CVE-2018-8581 advisory for the exact builds covered. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-03 with known ransomware use, confirming in-the-wild exploitation, and EPSS assigns a 27.4% probability of exploitation in the next 30 days (98th percentile). No public proof-of-concept is known, but the KEV listing and ransomware linkage make patching exposed Exchange servers urgent.
What to do: Apply Microsoft's Exchange security updates per vendor instructions, as required by the CISA KEV listing, and confirm the patched build for your Exchange version in Microsoft's CVE-2018-8581 advisory since affected version ranges are not enumerated in this data. Because ransomware operators are known to exploit this flaw, prioritize internet-facing Exchange servers and hunt for signs of compromise — unexpected user impersonation, anomalous mailbox access, and post-exploitation activity — before and after patching.
| Microsoft Exchange Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.
- Affected
- Microsoft Exchange Server
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- exchange server
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N