Executive brief
Microsoft Exchange Server, the widely used corporate email and calendaring platform, is affected by a code injection vulnerability. An unauthorized attacker could exploit this flaw over the network to execute malicious code on the server. Successful exploitation could lead to a complete compromise of the email system, including unauthorized access to sensitive communications and potential disruption of business operations.
Technical details
A code injection vulnerability (CWE-94) exists in Microsoft Exchange Server due to improper control of code generation. The vulnerability can be exploited by an unauthenticated attacker over the network, though the CVSS vector indicates high attack complexity and requires user interaction (UI:R). If successfully exploited, the attacker can achieve full remote code execution (RCE) on the affected server, impacting confidentiality, integrity, and availability. Microsoft has released information regarding this vulnerability via their Security Update Guide, and administrators should apply the relevant security patches to mitigate the risk.
Affected products
- Microsoft Exchange Server
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Published by Microsoft and NVD