CVE-2026-55009: Microsoft Exchange Server Elevation of Privilege Vulnerability
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
Other sources
Microsoft Exchange Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1544.043Patch KB5103214 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1748.048Patch KB5103213 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.2562.045Patch KB5103212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.071Patch KB5103215
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55009?
The severity of CVE-2026-55009 is rated high with a score of 7.8.
How do I fix CVE-2026-55009?
To fix CVE-2026-55009, apply the security updates provided by Microsoft for affected versions of Exchange Server.
What impact does CVE-2026-55009 have?
CVE-2026-55009 allows an authorized attacker to elevate privileges locally within Microsoft Exchange Server.
Which versions of Microsoft Exchange Server are affected by CVE-2026-55009?
CVE-2026-55009 affects Microsoft Exchange Server 2019, Microsoft Exchange Server 2016, and Microsoft Exchange Server Subscription Edition RTM.
Is CVE-2026-55009 related to deserialization vulnerabilities?
Yes, CVE-2026-55009 involves the deserialization of untrusted data, which can lead to privilege escalation.