Lucene search

K
kasperskyKaspersky LabKLA11518
HistoryJul 09, 2019 - 12:00 a.m.

KLA11518 Multiple vulnerabilities in Microsoft Exchange Server

2019-07-0900:00:00
Kaspersky Lab
threats.kaspersky.com
77

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

7 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.1%

Multiple vulnerabilities were found in Microsoft Exchange Server. Malicious users can exploit these vulnerabilities to spoof user interface, gain privileges, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A spoofing vulnerability in Microsoft Exchange Server can be exploited remotely via specially crafted web to spoof user interface.
  2. An elevation of privilege vulnerability in Microsoft Exchange Server can be exploited remotely to gain privileges.
  3. An information disclosure vulnerability in Microsoft Exchange can be exploited remotely to obtain sensitive information.

Original advisories

CVE-2019-1137

CVE-2019-1136

CVE-2019-1084

ADV190021

Related products

Microsoft-Exchange-Server

CVE list

CVE-2019-1084 warning

CVE-2019-1137 warning

CVE-2019-1136 high

KB list

4509410

4509409

4509408

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

  • SUI

Spoof user interface. Exploitation of vulnerabilities with this impact can lead to changes in user interface to beguile user into inaccurate behavior.

Affected Products

  • Microsoft Exchange Server 2016 Cumulative Update 13Microsoft Exchange Server 2019 Cumulative Update 1Microsoft Exchange Server 2013 Cumulative Update 23Microsoft Exchange Server 2019 Cumulative Update 2Microsoft Exchange Server 2016 Cumulative Update 12Microsoft Exchange Server 2010 Service Pack 3Microsoft Office 2016 (32-bit edition)Microsoft Outlook 2013 Service Pack 1 (32-bit editions)Microsoft Lync Basic 2013 Service Pack 1 (64-bit)Microsoft Outlook 2013 Service Pack 1 (64-bit editions)Skype for Business 2016 (64-bit)Microsoft Office 2016 (64-bit edition)Microsoft Office 2016 for MacSkype for Business 2016 (32-bit)Microsoft Office 2019 for MacMicrosoft Lync Basic 2013 Service Pack 1 (32-bit)Outlook for iOSMicrosoft Outlook 2016 (64-bit edition)Microsoft Outlook 2010 Service Pack 2 (64-bit editions)Microsoft Lync 2013 Service Pack 1 (32-bit)Office 365 ProPlus for 32-bit SystemsMicrosoft Outlook 2016 (32-bit edition)Microsoft Outlook 2010 Service Pack 2 (32-bit editions)Mail and CalendarMicrosoft Outlook for AndroidOffice 365 ProPlus for 64-bit SystemsMicrosoft Lync 2013 Service Pack 1 (64-bit)Microsoft Office 2019 for 32-bit editionsMicrosoft Office 2013 RT Service Pack 1Microsoft Office 2019 for 64-bit editionsMicrosoft Office 2013 Service Pack 1 (32-bit editions)Skype for Business 2016 Basic (64-bit)Microsoft Office 2013 Service Pack 1 (64-bit editions)Skype for Business 2016 Basic (32-bit)

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

7 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.1%