CVE-2026-62910 Microsoft Exchange Server Elevation of Privilege Vulnerability
7.2
Analisi su rafaelpfister.ch
Descrizione del produttore (in inglese)
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. Dati di riferimento
- Produttore
- Microsoft
- Prodotti interessati
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server Subscription Edition RTM
- CVSS 3.1
- 7.2 (HIGH)
- Vettore
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C- Tipo di debolezza
- CWE-99: Improper Control of Resource Identifiers ('Resource Injection')
- Pubblicata
- 11 agosto 2026