Impact
The vulnerability is caused by the deserialization of untrusted data, allowing an attacker with authorized access to send crafted payloads that trigger a crash of the Exchange service, resulting in a denial of service. The weakness is categorized as CWE‑502, which involves handling of untrusted data leading to security failures. Because the crash terminates the service, the attack can interrupt communication, potentially affecting email availability for users.
Affected Systems
This issue affects Microsoft Exchange Server 2016 when it is running Cumulative Update 23, Exchange Server 2019 when it is running Cumulative Update 14 or 15, and the Exchange Server Subscription Edition at RTM. All affected versions require the server to be within the respective update levels for mitigation.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is considered moderate to high severity. The EPSS score of 1% indicates a very low but nonzero probability of exploitation, and it is not listed in the CISA KEV catalog, suggesting that no documented public exploits are known. The attack requires an authorized user and is carried out over the network, so the risk is limited to trusted connections. Nevertheless, the potential to interrupt service for an entire organization makes it a priority to remediate.
OpenCVE Enrichment