ZDI-26-534: (Pwn2Own) Microsoft Exchange Capture-Replay Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of Microsoft Exchange. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-62911.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-534?
ZDI-26-534 has a CVSS rating of 8.1, indicating a high severity vulnerability.
How do I fix ZDI-26-534?
To fix ZDI-26-534, ensure that you apply the latest security patches provided by Microsoft for affected versions of Exchange.
What systems are affected by ZDI-26-534?
ZDI-26-534 affects installations of Microsoft Exchange that are not updated with the latest security patches.
Can ZDI-26-534 be exploited remotely?
Yes, ZDI-26-534 can be exploited remotely without authentication.
What is the consequence of ZDI-26-534 being exploited?
If exploited, ZDI-26-534 allows attackers to bypass authentication, potentially leading to unauthorized access to sensitive information.