Showing 25 vulnerabilities on this page for Microsoft Exchange Server 2019 Cumulative Update 14

Signals CISA KEV Ransomware Nuclei
Microsoft vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Microsoft Exchange Server Elevation of Privilege Vulnerability

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

CWE-294Aug 11, 2026
CVSS8.0v3.1EPSS0.732%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

CWE-918Aug 11, 2026
CVSS6.5v3.1EPSS0.616%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Security Feature Bypass Vulnerability

Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

CWE-862Aug 11, 2026
CVSS6.5v3.1EPSS0.494%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

CWE-79Aug 11, 2026
CVSS7.3v3.1EPSS0.532%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

CWE-122Aug 11, 2026
CVSS8.8v3.1EPSS0.618%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Denial of Service Vulnerability

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.

CWE-502Aug 11, 2026
CVSS6.5v3.1EPSS1.31%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Elevation of Privilege Vulnerability

Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

CWE-99Aug 11, 2026
CVSS7.2v3.1EPSS0.697%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Elevation of Privilege Vulnerability

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

CWE-502Jul 14, 2026
CVSS7.8v3.1EPSS1.61%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

CWE-79Jul 14, 2026
CVSS9.6v3.1EPSS0.85%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Elevation of Privilege Vulnerability

Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

CWE-1220Jul 14, 2026
CVSS7.8v3.1EPSS0.214%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

CWE-122Jul 14, 2026
CVSS8.8v3.1EPSS0.664%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

CWE-79Jun 9, 2026
CVSS8.1v3.1EPSS0.353%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Remote Code Execution Vulnerability

Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

CWE-94Jun 9, 2026
CVSS7.5v3.1EPSS0.475%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

CWE-918Jun 9, 2026
CVSS8.8v3.1EPSS0.846%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Information Disclosure Vulnerability

Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

CWE-285CWE-918Jun 9, 2026
CVSS8.1v3.1EPSS0.445%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Information Disclosure Vulnerability

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

CWE-918Jun 9, 2026
CVSS5.0v3.1EPSS20.3%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Spoofing Vulnerability

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

CWE-79CWE-918Jun 9, 2026
CVSS6.5v3.1EPSS0.308%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

CWE-79Jun 9, 2026
CVSS6.1v3.1EPSS0.375%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

CWE-79May 14, 2026
CVSS8.1v3.1EPSS70.3%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Spoofing Vulnerability

User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

CVSS6.5v3.1EPSS7.68%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Elevation of Privilege Vulnerability

Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

CWE-20Dec 9, 2025
CVSS7.5v3.1EPSS1.04%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Spoofing Vulnerability

User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

CWE-451Dec 9, 2025
CVSS5.3v3.1EPSS0.808%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Spoofing Vulnerability

Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

CWE-20Oct 14, 2025
CVSS7.5v3.1EPSS0.951%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Elevation of Privilege Vulnerability

Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

CWE-1390Oct 14, 2025
CVSS8.8v3.1EPSS0.771%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft Exchange Server Elevation of Privilege Vulnerability

Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.

CWE-303Oct 14, 2025
CVSS8.4v3.1EPSS0.333%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX