CVE-2024-26198HighCVSS 8.8

Microsoft Exchange Server Remote Code Execution Vulnerability

Published
March 12, 2024
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? An unauthenticated attacker could exploit the vulnerability by placing a specially crafted file onto an online directory or in a local network location then convincing the user to open it. In a successful attack, this will then load a malicious DLL which could lead to a remote code execution.

According to the CVSS metric, the attack vector is network (AV:N) and the user interaction is required (UI:R). What is the target context of the remote code execution? This attack requires a specially crafted file to be placed either in an online directory or in a local network location. When a victim runs this file, it loads the malicious DLL.

🎯 Affected products3

  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server 2019 Cumulative Update 13
  • Microsoft Exchange Server 2019 Cumulative Update 14

✅ Remediation

KB5037224 (Security Update) — fixed build 15.02.1258.034 KB5037224 (Security Update) — fixed build 15.02.1544.011 KB5037224 (Security Update) — fixed build 15.01.2507.039

🔗 References (4)