Impact
A heap-based buffer overflow in Microsoft Exchange Server permits an attacker with authorized credentials to execute arbitrary code on the server, potentially compromising confidentiality, integrity, and availability. The vulnerability is classified as CWE-122 and has a CVSS score of 8.8, indicating a high severity flaw.
Affected Systems
The flaw affects Microsoft Exchange Server 2016 running Cumulative Update 23, Microsoft Exchange Server 2019 running Cumulative Updates 14 and 15, and Microsoft Exchange Server Subscription Edition at Release to Manufacturing. No other versions or products are listed as affected.
Risk and Exploitability
Based on the description, it is inferred that the vulnerability requires an authenticated attacker who can reach the Exchange services over the network. The CVSS score of 8.8 signals a high risk, while the EPSS score is not available and the flaw is not listed in the CISA KEV catalog. This suggests that although widely known, exploitation may still be in early stages, but the high severity warrants prompt action.
OpenCVE Enrichment