Executive brief
A security vulnerability has been identified in Microsoft Exchange Server, the platform used by organizations for email and calendaring. An attacker with basic user credentials could exploit this flaw to take control of the server and execute malicious commands. This could lead to a total compromise of the email system, including unauthorized access to sensitive communications and disruption of business operations.
Technical details
A heap-based buffer overflow (CWE-122) exists in Microsoft Exchange Server. The vulnerability is reachable over the network and requires low-privileged user authentication (PR:L), but no user interaction. By sending a specially crafted request to the server, an attacker can trigger the overflow to achieve remote code execution (RCE) in the context of the Exchange service. Affected versions include Exchange Server 2016, 2019, and the Subscription Edition; Microsoft has released security updates to address this issue.
Affected products
- Microsoft Exchange Server 2016 Cumulative Update 23 15.01.0.0 to 15.01.2507.071
- Microsoft Exchange Server 2019 Cumulative Update 14 15.02.0.0 to 15.02.1544.043
- Microsoft Exchange Server 2019 Cumulative Update 15 15.02.0.0 to 15.02.1748.048
- Microsoft Exchange Server Subscription Edition RTM 15.02.0.0 to 15.02.2562.045
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory: Microsoft released security updates for affected versions.