Impact
The vulnerability is a heap-based buffer overflow in Microsoft Exchange Server that permits an authorized attacker to execute code on the server from the network. The flaw enables full control of the affected system, potentially compromising confidential data, integrity, and availability. Based on the description, it is inferred that the overflow is triggered by sending maliciously crafted input over the network.
Affected Systems
The affected systems are Microsoft Exchange Server 2016 running Cumulative Update 23, Microsoft Exchange Server 2019 running Cumulative Update 14 or 15, and Microsoft Exchange Server Subscription Edition in its RTM configuration. All instances running these specific updates are vulnerable; earlier or later releases are not affected.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of <1% shows that this flaw is not heavily exploited at present. The vulnerability is not listed in the CISA KEV catalog, suggesting that it has not been observed in the wild. The likely attack vector is an authorized user on the network sending maliciously crafted requests, based on the description. Because the attack requires only authorized credentials, malicious insiders or compromised service accounts could exploit it, leading to a complete loss of confidentiality, integrity, and availability if successful.
OpenCVE Enrichment