« Back to list

CVE-2018-8159

Status: ModifiedMedium (5.4)—

An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2018-8159",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "secure@microsoft.com",
      "affectedData": [
        {
          "vendor": "Microsoft",
          "product": "Microsoft Exchange Server",
          "versions": [
            {
              "status": "affected",
              "version": "2013 Cumulative Update 19"
            },
            {
              "status": "affected",
              "version": "2013 Cumulative Update 20"
            },
            {
              "status": "affected",
              "version": "2016 Cumulative Update 8"
            },
            {
              "status": "affected",
              "version": "2016 Cumulative Update 9"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-05-09T19:29:02.497",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/104056",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1040850",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "secure@microsoft.com"
    },
    {
      "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8159",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/104056",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1040850",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8159",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka \"Microsoft Exchange Elevation of Privilege Vulnerability.\" This affects Microsoft Exchange Server."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad de elevación de privilegios cuando Microsoft Exchange Outlook Web Access (OWA) fracasa a la hora de gestionar correctamente peticiones web. Esto también se conoce como \"Microsoft Exchange Elevation of Privilege Vulnerability\". Esto afecta a Microsoft Exchange Server."
    }
  ],
  "lastModified": "2026-06-17T02:04:22.280",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_19:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20E4796E-3E9B-473E-A7E3-498540185FBF"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_20:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8076F450-BC75-420B-99F7-05D3CCA50E74"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "075E907F-AF2F-4C31-86C7-51972BE412A1"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "69AF19DC-3D65-49A8-A85F-511085CDF27B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@microsoft.com"
}