Socprime
Critical RCE Vulnerability in Microsoft Exchange Server Disclosed
Article Content
A critical pre-authentication remote code execution vulnerability, CVE-2026-62911, affects Microsoft Exchange Server due to inadequate enforcement of Extended Protection on the MRSProxy HTTP.sys endpoint. Attackers can exploit this flaw via an NTLM relay, gaining machine account privileges and potentially achieving SYSTEM-level control. The vulnerability was demonstrated at Pwn2Own Berlin 2026 and has a public proof-of-concept available. Organizations using affected versions of Exchange should apply Microsoft security updates KB5121576, KB5121575, KB5121574, or KB5121573. Exchange 2016, which reached end-of-life in October 2025, requires Extended Security Updates for continued protection. Security teams are advised to monitor for unauthorized file creation and unusual WCF service activity. The situation is urgent as the PoC code is publicly available, increasing the risk of exploitation.
Key Points: • CVE-2026-62911 allows pre-auth RCE on Microsoft Exchange Server. • Public PoC code released following demonstration at Pwn2Own Berlin 2026. • Organizations must apply Microsoft security updates to mitigate risks.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.