Executive brief
Microsoft Exchange Server is the email and collaboration platform used by many organizations to handle internal and external communications. A double free memory corruption vulnerability allows an unauthenticated attacker on a network to execute arbitrary code on the affected server, potentially compromising email data, enabling lateral movement within the organization, and disrupting email services.
Technical details
The vulnerability is a double free (memory corruption) in Microsoft Exchange Server, allowing unauthenticated remote code execution. The defect permits an attacker on the network to trigger the unsafe memory deallocation, leading to arbitrary code execution with the privileges of the Exchange process. No authentication is required and the attack is network-accessible, making it exploitable from outside the organization's perimeter. Patches are available from Microsoft via their Security Response Center.
Affected products
- Microsoft Exchange Server
Timeline
- 2026-09-08: disclosed: Published on NVD and Microsoft Security Response Center