ZeroHour

CVE-2018-8581

KEV ransomwaremass

Privilege Escalation (Arbitrary User Impersonation) in Microsoft Exchange Server

CISA: Microsoft Exchange Server Privilege Escalation Vulnerability

CVSS 3.1
7.4 high
EPSS
27%p98
Published
()
KEV added
AI analysis

CVE-2018-8581 is a privilege escalation vulnerability in Microsoft Exchange Server that, when successfully exploited, allows an attacker to impersonate any other user of the Exchange server. Impersonating an arbitrary user lets the attacker act as that user — reading their mailbox, sending messages as them, and, if the impersonated account is privileged or administrative, gaining elevated access to the messaging environment. Organizations running on-premises Microsoft Exchange Server are affected; the provided data does not specify the affected version ranges, so operators should consult Microsoft's CVE-2018-8581 advisory for the exact builds covered. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-03 with known ransomware use, confirming in-the-wild exploitation, and EPSS assigns a 27.4% probability of exploitation in the next 30 days (98th percentile). No public proof-of-concept is known, but the KEV listing and ransomware linkage make patching exposed Exchange servers urgent.

What to do: Apply Microsoft's Exchange security updates per vendor instructions, as required by the CISA KEV listing, and confirm the patched build for your Exchange version in Microsoft's CVE-2018-8581 advisory since affected version ranges are not enumerated in this data. Because ransomware operators are known to exploit this flaw, prioritize internet-facing Exchange servers and hunt for signs of compromise — unexpected user impersonation, anomalous mailbox access, and post-exploitation activity — before and after patching.

Affected
Microsoft Exchange Server
Estimated exposure
mass≈ hundreds of thousands of on-premises Exchange deployments (millions of mailbox users) — Exchange is one of the most widely deployed corporate email platforms, and public internet scans have long shown on the order of hundreds of thousands of exposed Exchange/OWA endpoints, each typically serving many users; with a meaningful…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.

CISA Known Exploited Vulnerability
Affected
Microsoft Exchange Server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
exchange server
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news