Executive brief
A security vulnerability in Microsoft Exchange Server, the platform used by organizations for email and calendaring, could allow an attacker with existing low-level access to gain full administrative control. By exploiting how the server processes certain data, an authorized user can bypass security restrictions to perform unauthorized actions. This could lead to the theft of sensitive emails, disruption of communication services, or further compromise of the corporate network.
Technical details
A deserialization vulnerability (CWE-502) exists in Microsoft Exchange Server due to the insecure handling of untrusted data. An attacker with local access and low-level privileges can exploit this flaw by providing specially crafted serialized data to the server, which, when processed, allows for arbitrary code execution or privilege escalation. The attack vector is local, meaning the attacker must already have a foothold on the system or be an authenticated user with local access. Successful exploitation grants the attacker high-level system privileges, potentially leading to full compromise of the Exchange environment. Microsoft has released security updates to address this issue across affected versions of Exchange Server 2016, 2019, and the Subscription Edition.
Affected products
- Microsoft Exchange Server 2016 Cumulative Update 23 < 15.01.2507.071
- Microsoft Exchange Server 2019 Cumulative Update 14 < 15.02.1544.043
- Microsoft Exchange Server 2019 Cumulative Update 15 < 15.02.1748.048
- Microsoft Exchange Server Subscription Edition RTM < 15.02.2562.045
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory