ZDI-CAN-31480: ZDI-26-538: (Pwn2Own) Microsoft Exchange Improper Authorization Privilege Escalation Vulnerability
This vulnerability allows remote attackers to escalate privileges on affected installations of Microsoft Exchange. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-62911.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-31480?
ZDI-CAN-31480 has a CVSS rating of 8.8, indicating a high severity level.
How do I fix ZDI-CAN-31480?
To mitigate ZDI-CAN-31480, apply the latest security updates and patches provided by Microsoft for Exchange.
What type of vulnerability is ZDI-CAN-31480?
ZDI-CAN-31480 is an improper authorization privilege escalation vulnerability.
Who can exploit ZDI-CAN-31480?
Remote attackers with valid authentication credentials can exploit ZDI-CAN-31480 by bypassing the existing authentication mechanism.
What are the potential impacts of ZDI-CAN-31480?
The potential impact of ZDI-CAN-31480 includes unauthorized privilege escalation on affected Microsoft Exchange installations.