Microsoft Exchange Server Elevation of Privilege Vulnerability via Server-Side Request Forgery

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in Microsoft Exchange Server. This vulnerability allows an authorized attacker to elevate privileges over the network. Exploitation could enable the attacker to access restricted information or perform actions typically reserved for users with higher privileges or administrators.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing attackers to access mailboxes and Exchange services as if they were another user.

Remediation

Users can download the security update for this vulnerability through the Microsoft Update Catalog. Instructions for applying the update are available in the Microsoft Knowledge Base articles linked in the 'Security Updates' section.

Added: Jun 9, 2026, 6:37 PM
Updated: Jun 9, 2026, 6:37 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.9
exploitability
4.7
remediation
0.0
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.