Elevation of Privilege Vulnerability in Microsoft Exchange Server by Microsoft
CVE-2026-55009

7.8HIGH

What is CVE-2026-55009?

An elevation of privilege vulnerability exists in Microsoft Exchange Server due to improper handling of deserialization of untrusted data. An attacker who successfully exploits this vulnerability could execute arbitrary code with elevated permissions on the system, potentially compromising sensitive data and system integrity. Microsoft has issued a patch to mitigate this issue, urging prompt updates to all affected versions.

Affected Version(s)

Microsoft Exchange Server 2016 Cumulative Update 23 x64-based Systems 15.01.0.0 < 15.01.2507.071

Microsoft Exchange Server 2019 Cumulative Update 14 x64-based Systems 15.02.0.0 < 15.02.1544.043

Microsoft Exchange Server 2019 Cumulative Update 15 x64-based Systems 15.02.0.0 < 15.02.1748.048

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.