#VU15258 Privilege escalation in Microsoft Exchange Server - CVE-2018-8448
Published: October 9, 2018 / Updated: March 16, 2019
Microsoft Exchange Server
Microsoft
Description
The vulnerability exists due to improper handling of web requests within Microsoft Exchange Outlook Web Access (OWA). A remote unauthenticated attacker can send a specially crafted email message containing a malicious link, trick the victim into clicking it and gain elevated privileges to conduct further attacks.