QID 150834
Date Published: 2024-03-19
QID 150834: Microsoft Exchange Server Remote Code Execution (RCE) Vulnerability (CVE-2024-26198)
Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft. It runs exclusively on Windows Server operating systems.
Multiple versions of Microsoft Exchange Server are affected by a Remote Code Execution (RCE) Vulnerability when loading malicious DLL files.
Affected Products:
Exchange Server 2019 Cumulative Update 14
Exchange Server 2019 Cumulative Update 13
Exchange Server 2016 Cumulative Update 23
QID Detection Logic: (Unauthenticated)
This QID sends a HTTP GET request to "/owa" endpoint and checks for vulnerable version of Microsoft Exchange Server.
Successful exploitation of this vulnerability could allow an unauthenticated attacker to load a malicious DLL file which could lead to Remote Code Execution (RCE).
Exchange Server 2019 Cumulative Update 14 - KB5036401
Exchange Server 2019 Cumulative Update 13 - KB5036402
Exchange Server 2016 Cumulative Update 23 - KB5036386
For more information pertaining to this vulnerability please refer Microsoft Security Advisory.
- Microsoft Security Advisory -
msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26198
CVEs related to QID 150834
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| KB5036386 |
|
||
| KB5036401 |
|
||
| KB5036402 |
|