CVE-2018-0941

Description

Microsoft Exchange Server 2016 Cumulative Update 7 and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how data is imported, aka Microsoft Exchange Information Disclosure Vulnerability. This CVE is unique from CVE-2018-0924.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
28.949

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Exchange Information Disclosure Vulnerability for Exchange Server 2013 SP1 (KB4073392)Windows
Microsoft Exchange Information Disclosure Vulnerability for Exchange Server 2013 CU18 (KB4073392)Windows
Microsoft Exchange Information Disclosure Vulnerability for Exchange Server 2013 CU19 (KB4073392)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-24169Security Update For Exchange Server 2013 SP1 (KB4073392)
PATCH-24170Security Update For Exchange Server 2013 CU18 (KB4073392)
PATCH-24171Security Update For Exchange Server 2013 CU19 (KB4073392)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234