Executive brief
Microsoft Exchange Server, the primary platform for corporate email and calendaring, contains a security flaw that allows a user with low-level access to gain higher administrative privileges. An attacker who already has a foothold on the server could exploit this to take full control of the email environment, potentially accessing sensitive communications or disrupting operations. This vulnerability requires the attacker to have local access to the system rather than being exploitable directly over the internet.
Technical details
A privilege escalation vulnerability exists in Microsoft Exchange Server due to insufficient granularity of access control (CWE-1220). The flaw allows a locally authenticated attacker with low-level privileges to gain elevated permissions on the affected system. The attack vector is local, meaning the attacker must already have the ability to execute code or access the server locally. Successful exploitation could lead to a complete compromise of confidentiality, integrity, and availability. Microsoft has released security updates for Exchange Server 2016, 2019, and the Subscription Edition to address this issue.
Affected products
- Microsoft Exchange Server 2016 Cumulative Update 23 15.01.0.0 to 15.01.2507.071
- Microsoft Exchange Server 2019 Cumulative Update 14 15.02.0.0 to 15.02.1544.043
- Microsoft Exchange Server 2019 Cumulative Update 15 15.02.0.0 to 15.02.1748.048
- Microsoft Exchange Server Subscription Edition RTM 15.02.0.0 to 15.02.2562.045
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory