4.3
CVE-2018-8151
- EPSS 8.77%
- Veröffentlicht 09.05.2018 19:29:02
- Zuletzt bearbeitet 21.11.2024 04:13:21
- Erkennungen
An information disclosure vulnerability exists when Microsoft Exchange improperly handles objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8154.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Exchange Server Version 2010 Update sp3
Microsoft ≫ Exchange Server Version 2013 Update cumulative_update_19
Microsoft ≫ Exchange Server Version 2013 Update cumulative_update_20
Microsoft ≫ Exchange Server Version 2013 Update sp1
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_8
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 8.77% | 0.947 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://www.securityfocus.com/bid/104042
http://www.securitytracker.com/id/1040850
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8151