Microsoft Exchange Server Vulnerabilities Enables DoS, Privilege Escalation and RCE Attacks

Microsoft has launched safety updates for a number of Trade Server vulnerabilities that might permit denial-of-service, privilege escalation, distant code execution, spoofing, and safety function bypass assaults.

The failings have been disclosed on August 11, 2026, as part of Microsoft’s monthly Patch Tuesday release. Trade Server Subscription Version, Trade Server 2019, and Trade Server 2016 are among the many supported merchandise receiving safety updates.

Essentially the most critical challenge is CVE-2026-62911, a crucial elevation-of-privileges vulnerability with a CVSS rating of 8.0. The flaw is linked to CWE-294, referred to as authentication bypass by capture-replay.

An attacker with low privileges may exploit the difficulty over a community if they will persuade a person to work together with a malicious request or useful resource.

Profitable exploitation may permit the attacker to realize larger permissions throughout the Trade atmosphere. Safety researchers have highlighted CVE-2026-62911 as a serious concern as a result of it was demonstrated at Pwn2Own Berlin.

Microsoft Trade Server Vulnerabilities

Stories state that exploitation might allow an attacker to bypass authentication protections and entry Trade mailboxes, together with the power to learn messages, ship emails, and obtain attachments.

Though Microsoft lists exploit code maturity as unproven, the general public demonstration means defenders ought to deal with the vulnerability as a high-priority patching challenge.

One other elevation-of-privilege flaw, CVE-2026-62910, has a CVSS rating of seven.2 and is brought on by improper management of useful resource identifiers, often known as useful resource injection.

The vulnerability requires excessive privileges, however exploitation is network-based and doesn’t require person interplay. A menace actor with approved entry may abuse crafted requests to realize extra permissions and increase management over Trade companies.

Affected Vulnerabilities and CVEs:

CVE ID Vulnerability kind Assault necessities Safety influence
CVE-2026-62910 Elevation of Privilege Community assault, low complexity, excessive privileges required, no person interplay A licensed attacker may elevate privileges, probably gaining SYSTEM-level entry
CVE-2026-62911 Elevation of Privilege Community assault, low complexity, low privileges required, person interplay required An attacker may bypass authentication controls and elevate privileges in Trade Server
CVE-2026-62912 Denial of Service Community assault, low complexity, low privileges required, no person interplay An attacker may trigger Trade Server service disruption or unavailability
CVE-2026-62913 Distant Code Execution Community assault, low complexity, low privileges required, no person interplay An attacker may execute code on a weak Trade Server, affecting confidentiality, integrity, and availability
CVE-2026-62914 Spoofing Community assault, low complexity, low privileges required, person interplay required An attacker may use malicious net content material to spoof trusted Trade-related content material or goal customers
CVE-2026-62915 Safety Characteristic Bypass Community assault, low complexity, low privileges required, no person interplay An attacker may bypass authorization checks and carry out unauthorized actions affecting knowledge integrity

Microsoft additionally mounted CVE-2026-62912, a denial-of-service vulnerability brought on by deserialization of untrusted knowledge. The flaw has a CVSS rating of 6.5 and requires low privileges to take advantage of.

An attacker may exploit it remotely with out person interplay to disrupt the provision of an Trade Server. Whereas it doesn’t straight have an effect on confidentiality or integrity, a profitable assault may interrupt e mail supply, administrative operations, and enterprise communications.

CVE-2026-62913 is a remote code execution vulnerability with a CVSS rating of 8.8. The difficulty entails a heap-based buffer overflow and will be exploited over a community by an attacker with low privileges.

No person interplay is required. If exploited efficiently, the flaw may permit an attacker to run code on a weak Trade Server, probably resulting in mailbox theft, persistence, lateral motion, knowledge theft, or ransomware deployment.

The replace additionally addresses CVE-2026-62914, a cross-site scripting spoofing vulnerability, and CVE-2026-62915, a safety function bypass brought on by lacking authorization controls.

These points may assist attackers impersonate trusted content material, goal Trade customers, or make unauthorized modifications in affected environments. Organizations ought to set up Microsoft’s August 2026 Trade Server security updates as quickly as doable.

Directors must also evaluate privileged accounts, monitor Trade logs for irregular authentication exercise, examine uncommon mailbox entry, and prohibit pointless distant administrative entry.

Trade On-line clients are already protected against these server-side flaws. Nevertheless, organizations working on-premises Trade Server or Trade administration instruments ought to apply the related updates immediately.

 Strengthen Your SOC by Accelerating Risk Detection & Fast Investigations. -> Integrate ANY.RUN With Your SOC Now.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *