PT-2024-2081 · Microsoft · Exchange Server

Kap0K

+1

·

Published

2024-03-12

·

Updated

2024-12-06

·

CVE-2024-26198

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server (affected versions not specified)
Description The issue is related to an uncontrolled search path element when loading DLL libraries in Microsoft Exchange Server. This can allow a remote attacker to execute arbitrary code. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Uncontrolled Search Path Element

Untrusted Search Path

Weakness Enumeration

Related Identifiers

BDU:2024-01975
CVE-2024-26198

Affected Products

Exchange Server