CVE-2018-0924 is an information disclosure vulnerability affecting multiple versions of Microsoft Exchange Server, including Exchange Server 2010 SP3 UR20, Exchange Server 2013 CU18/CU19/SP1, and Exchange Server 2016 CU7/CU8. The vulnerability stems from improper handling of URL redirects, potentially allowing an unauthenticated attacker to gain access to sensitive information. With a CVSS score of 6.5 (Medium), it has a network attack vector and low attack complexity, requiring user interaction to exploit, and leading to high confidentiality impact. While not currently listed in CISA's KEV catalog or having public exploit code, it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2010:sp3_rollup20:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_18:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_19:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2013:sp1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_7:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.