Remote Code Execution Vulnerability Affects Microsoft Exchange Server
CVE-2024-26198

8.8HIGH

Key Information:

Badges

πŸ‘Ύ Exploit ExistsπŸ“° News Worthy

Summary

The vulnerability in Microsoft Exchange Server allows attackers to execute arbitrary code with elevated privileges. This results from improper input validation, enabling unauthorized actions on the affected system. Attackers could exploit this flaw through specially crafted requests, posing significant risks to data integrity and security. Organizations using vulnerable versions of Exchange Server should prioritize applying the necessary security updates to mitigate potential exploits.

Affected Version(s)

Microsoft Exchange Server 2016 Cumulative Update 23 x64-based Systems 15.01.0 < 15.01.2507.039

Microsoft Exchange Server 2019 Cumulative Update 13 x64-based Systems 15.02.0 < 15.02.1544.011

Microsoft Exchange Server 2019 Cumulative Update 14 x64-based Systems 15.02.0 < 15.02.1258.034

News Articles

17,000+ Microsoft Exchange servers in Germany are vulnerable to attack, BSI warns - Help Net Security

At least 17,000 instances of Microsoft Exchange servers in Germany - and likely more of them - are vulnerable to one or more critical flaws.

9 months ago

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ“°

    First article discovered by Help Net Security

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed0 Proof of Concept(s)1 News Article(s)
.