ZDI-CAN-31481: ZDI-26-535: (Pwn2Own) Microsoft Exchange External Control of File Path Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Exchange. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-62911.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-31481?
The severity of ZDI-CAN-31481 is rated at 7.2 based on the CVSS score.
How do I fix ZDI-CAN-31481?
To remediate ZDI-CAN-31481, ensure that you apply the latest security patches for Microsoft Exchange.
Can ZDI-CAN-31481 be exploited without authentication?
No, ZDI-CAN-31481 requires authentication to exploit, but the authentication mechanism can be bypassed.
What type of attack does ZDI-CAN-31481 facilitate?
ZDI-CAN-31481 allows remote code execution, enabling attackers to execute arbitrary code on affected systems.
Which software is affected by ZDI-CAN-31481?
ZDI-CAN-31481 affects installations of Microsoft Exchange.