{
    "id": "CVE-2018-8154",
    "published": "2018-05-09 19:29:02",
    "last_modified": "2026-06-17 02:04:21",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.0",
    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-787",
    "description": "A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka \"Microsoft Exchange Memory Corruption Vulnerability.\" This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8151.",
    "epss_score": "0.24055",
    "epss_percentile": "0.97783",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-03 18:17:22",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "EPSS 24.1% — above the 10% action threshold."
    },
    "products": [
        {
            "vendor": "microsoft",
            "product": "exchange_server"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "http://www.securityfocus.com/bid/104054",
        "http://www.securitytracker.com/id/1040850",
        "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8154",
        "http://www.securityfocus.com/bid/104054",
        "http://www.securitytracker.com/id/1040850",
        "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8154"
    ]
}