Impact
Microsoft Exchange Server permits an authorized local attacker to elevate privileges on the affected system. The vulnerability resides in the handling of untrusted data during deserialization, which permits manipulation of the input stream in a manner defined by CWE-502. Once the attacker is able to supply crafted data, they can gain higher privileges than the account initially used, potentially compromising the entire Exchange installation.
Affected Systems
The flaw affects Microsoft Exchange Server 2016 version with Cumulative Update 23, Microsoft Exchange Server 2019 versions with Cumulative Update 14 and Cumulative Update 15, and Microsoft Exchange Server Subscription Edition RTM. These products are susceptible when they are running the indicated update levels without the latest patches.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score of 2% suggests a moderate probability that attackers will target this weakness in the near term. The vulnerability is not listed in the CISA KEV catalog, but the combination of a known deserialization vulnerability and local privilege escalation remains significant. An attacker must possess local authorized access to the Exchange Server to exploit the issue; the attack vector is thus local and requires the attacker to forge a deserialization payload that is accepted by the server. Once executed, the attacker may gain administrative rights and potentially access or modify sensitive corporate data.
OpenCVE Enrichment