First published: Wed Aug 15 2018(Updated: )
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2010-sp3 | |
Microsoft Exchange Server | =2013-cumulative_update_20 | |
Microsoft Exchange Server | =2013-cumulative_update_21 | |
Microsoft Exchange Server | =2016-cumulative_update_10 | |
Microsoft Exchange Server | =2016-cumulative_update_9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8302 is considered a critical severity vulnerability due to its potential for remote code execution.
To fix CVE-2018-8302, you should apply the latest security updates released by Microsoft for your affected Exchange Server version.
CVE-2018-8302 affects Microsoft Exchange Server versions 2010, 2013 (cumulative updates 20 and 21), and 2016 (cumulative updates 9 and 10).
CVE-2018-8302 is classified as a memory corruption vulnerability allowing remote code execution on Microsoft Exchange Server.
Yes, CVE-2018-8302 can be exploited remotely, allowing an attacker to execute arbitrary code on the affected server.