Impact
The vulnerability is a double‑free bug in Microsoft Exchange Server that allows an unauthorized attacker to execute arbitrary code via a network connection. The flaw arises when memory that has already been freed is accessed again, enabling exploitation through malicious crafted requests. This weakness is classified as CWE‑415.
Affected Systems
Affected versions include Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15, and Microsoft Exchange Server Subscription Edition RTM. All instances of these builds that have not applied a subsequent security update remain vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, and with no EPSS score available the likelihood of exploitation is uncertain but non‑zero. The vulnerability is not currently listed in CISA's KEV catalog, but the remote attack surface suggests it could be leveraged by attackers with network access. Based on the description, it is inferred that the likely attack vector is a network‑based request to the Exchange service, and the impact could be full remote code execution on the host.
OpenCVE Enrichment