CVE-2018-0941: Microsoft Exchange Server

Medium severity, CVSS 5.5. EPSS: 12.5% chance of exploitation in the next 30 days.

Microsoft Exchange Server 2016 Cumulative Update 7 and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how data is imported, aka "Microsoft Exchange Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0924.

Affected products

Published 2018-03-14. Last modified 2026-06-17.