ZDI-CAN-28462: ZDI-26-194: Microsoft Exchange InterceptorSmtpAgent Improper Input Validation Security Feature Bypass Vulnerability
This vulnerability allows remote attackers to bypass a security feature on affected installations of Microsoft Exchange. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-21527.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28462?
The severity of ZDI-CAN-28462 is critical due to its potential to allow remote attackers to bypass security features without authentication.
How do I fix ZDI-CAN-28462?
To fix ZDI-CAN-28462, apply the latest security updates provided by Microsoft for Microsoft Exchange.
What systems are affected by ZDI-CAN-28462?
ZDI-CAN-28462 affects installations of Microsoft Exchange that utilize the InterceptorSmtpAgent.
Can ZDI-CAN-28462 be exploited remotely?
Yes, ZDI-CAN-28462 can be exploited remotely since authentication is not required for the attack.
Is user interaction required to exploit ZDI-CAN-28462?
No, user interaction is not required to exploit ZDI-CAN-28462, making it easier for attackers to exploit.