CVE-2026-45504: Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
Other sources
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1544.043Patch KB5103214 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.071Patch KB5103215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1748.048Patch KB5103213 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.2562.045Patch KB5103212
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45504?
The severity of CVE-2026-45504 is high, with a score of 8.8.
How do I fix CVE-2026-45504?
To fix CVE-2026-45504, apply the latest security updates provided by Microsoft for your Exchange Server version.
What systems are affected by CVE-2026-45504?
CVE-2026-45504 affects Microsoft Exchange Server 2016, 2019, and the Subscription Edition.
What is the risk associated with CVE-2026-45504?
The risk associated with CVE-2026-45504 is an elevation of privilege that can be exploited by authorized attackers.
How does CVE-2026-45504 exploit server-side request forgery?
CVE-2026-45504 exploits server-side request forgery (SSRF) to enable unauthorized privilege escalation on the network.