CVE-2018-8153: Medium severity Microsoft Exchange Server vulnerability
Published May 9, 2018
·Updated
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Spoofing Vulnerability." This affects Microsoft Exchange Server.
Affected Software
2 affected components
Microsoft Exchange Server=2016-cumulative_update_8
Microsoft Exchange Server=2016-cumulative_update_9
Remediation
Event History
May 9, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8153?
The severity of CVE-2018-8153 is classified as important by Microsoft.
2
How do I fix CVE-2018-8153?
To fix CVE-2018-8153, you need to apply the latest cumulative update for Microsoft Exchange Server 2016.
3
Who is affected by CVE-2018-8153?
CVE-2018-8153 affects users of Microsoft Exchange Server 2016, specifically those on cumulative update 8 and 9.
4
What type of vulnerability is CVE-2018-8153?
CVE-2018-8153 is a spoofing vulnerability that impacts Outlook Web Access in Microsoft Exchange Server.
5
What can happen if CVE-2018-8153 is exploited?
If exploited, CVE-2018-8153 allows an attacker to impersonate users and potentially gain unauthorized access to sensitive information.