Skip to main content

Microsoft Exchange Memory Corruption Vulnerability

Microsoft have released details of a memory corruption vulnerability in the Exchange Server. An unauthenticated remote user could exploit this vulnerability to execute arbitrary code on an affected system.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Microsoft have released details of a memory corruption vulnerability in the Exchange Server. An unauthenticated remote user could exploit this vulnerability to execute arbitrary code on an affected system.


Affected platforms

The following platforms are known to be affected:

Threat details

The vulnerability lies in how Exchange Server handles application objects in memory. Specially crafted emails received by the server can result in corruption of the system memory, which an attacker could then exploit to execute scripts or applications sent in the email in the context of the System account.

For further information:


Remediation steps

Type Step

Microsoft addressed this vulnerability in their CVE-2019-0586 Security Update Guide. Users and administrators are encouraged to review this guide and apply the relevant updates.



CVE Vulnerabilities

Last edited: 11 January 2022 9:39 am