Описание
Microsoft Exchange Server Remote Code Execution Vulnerability
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
FAQ
How could an attacker exploit this vulnerability?
An unauthenticated attacker could send a specially crafted Visio attachment to an affected Exchange server. The server could process the attachment during content indexing, and successful exploitation could allow the attacker to execute code on the server. User interaction is not required.
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation requires the target system to be under sustained low-memory (memory pressure) conditions, which are not commonly present in normal operation. This makes the vulnerability difficult to reliably trigger, as the attacker must first induce or wait for a constrained memory state before exploitation becomes possible.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Microsoft Exchange Server 2019 Cumulative Update 14 | - | |
| Microsoft Exchange Server 2019 Cumulative Update 15 | - | |
| Microsoft Exchange Server Subscription Edition RTM |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
8.1 High
CVSS3
Связанные уязвимости
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
EPSS
8.1 High
CVSS3