Impact
External control of a file name or path in the Exchange Server allows an attacker who has authorized access to the system to execute arbitrary code over the network. The vulnerability, identified as CWE-73, permits remote code execution which can lead to full system compromise, data exfiltration or alteration.
Affected Systems
Microsoft Exchange Server 2016 cumulative update 23, Microsoft Exchange Server 2019 cumulative update 14 and 15, and Microsoft Exchange Server Subscription Edition RTM are affected. These versions must be identified and updated accordingly.
Risk and Exploitability
The CVSS score of 8.8 classifies this as a high severity vulnerability. While an EPSS score is not available, the fact that the vulnerability is not listed in CISA’s KEV means no large-scale exploitation has yet been observed, but the high CVSS indicates significant risk. The likely attack vector is a network-based exploitation that leverages an authenticated session with sufficient privileges to manipulate the file name or path.
OpenCVE Enrichment