Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-55007

Опубликовано: 08 сент. 2026
Источник: msrc
CVSS3: 8.1
EPSS Низкий

Описание

Microsoft Exchange Server Remote Code Execution Vulnerability

Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

FAQ

How could an attacker exploit this vulnerability?

An unauthenticated attacker could send a specially crafted Visio attachment to an affected Exchange server. The server could process the attachment during content indexing, and successful exploitation could allow the attacker to execute code on the server. User interaction is not required.

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?

Successful exploitation requires the target system to be under sustained low-memory (memory pressure) conditions, which are not commonly present in normal operation. This makes the vulnerability difficult to reliably trigger, as the attacker must first induce or wait for a constrained memory state before exploitation becomes possible.

Обновления

ПродуктСтатьяОбновление
Microsoft Exchange Server 2019 Cumulative Update 14
-
Microsoft Exchange Server 2019 Cumulative Update 15
-
Microsoft Exchange Server Subscription Edition RTM

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 53%
0.00726
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
16 дней назад

Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

CVSS3: 8.1
github
16 дней назад

Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

EPSS

Процентиль: 53%
0.00726
Низкий

8.1 High

CVSS3