First published: Wed Mar 14 2018(Updated: )
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how URL redirects are handled, aka "Microsoft Exchange Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0941.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2010-sp3_rollup20 | |
Microsoft Exchange Server | =2013-cumulative_update_18 | |
Microsoft Exchange Server | =2013-cumulative_update_19 | |
Microsoft Exchange Server | =2013-sp1 | |
Microsoft Exchange Server | =2016-cumulative_update_7 | |
Microsoft Exchange Server | =2016-cumulative_update_8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0924 is rated as critical due to its potential impact on Microsoft Exchange Server installations.
To address CVE-2018-0924, apply the latest cumulative updates and service packs for your version of Microsoft Exchange Server.
CVE-2018-0924 affects Microsoft Exchange Server 2010 SP3 Rollup 20, 2013 Cumulative Update 18 and 19, 2013 SP1, and 2016 Cumulative Updates 7 and 8.
Exploitation of CVE-2018-0924 could allow an attacker to execute arbitrary code on the affected Microsoft Exchange Server.
There are no specific workarounds for CVE-2018-0924; it is recommended to apply the available updates as soon as possible.