Microsoft COM Objects Race Condition Vulnerability in Inbox Components Allowing Local Code Execution
Vulnerability
A race condition vulnerability has been identified in Inbox COM Objects within Internet Information Services (IIS). This vulnerability allows an unauthorized attacker to execute code locally by exploiting concurrent execution with improper synchronization. The issue arises from a shared resource that can be manipulated to create a timing conflict, enabling code execution.
Impact
Exploitation of this vulnerability could lead to unauthorized local code execution.
Remediation
Users can apply the security update available through the Microsoft Update Catalog. For specific guidance, refer to the Microsoft Knowledge Base articles KB5066835, KB5066873, KB5066836, KB5066791, KB5066782, KB5066586, and KB5066793.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
