CVE-2019-0724

HIGH

Microsoft Exchange Privilege Escalation Exploit

Title source: metasploit
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-0724. PoCs published by _dirkjan, Petros Koutroumpis, including Metasploit module auxiliary/scanner/http/exchange_web_server_pushsubscription.

AI-analyzed exploit summary This Metasploit module exploits CVE-2019-0724, a privilege escalation vulnerability in Microsoft Exchange, by forcing the server to authenticate to an attacker-controlled URL via the PushSubscription feature. It leverages NTLM relaying to escalate privileges to those of the Exchange server.

Description

An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0686.

Exploits (1)

metasploit WORKING POC
by _dirkjan, Petros Koutroumpis · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/exchange_web_server_pushsubscription.rb

This Metasploit module exploits CVE-2019-0724, a privilege escalation vulnerability in Microsoft Exchange, by forcing the server to authenticate to an attacker-controlled URL via the PushSubscription feature. It leverages NTLM relaying to escalate privileges to those of the Exchange server.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Exchange Server 2013/2016
Auth required
Prerequisites: Valid domain user credentials with a mailbox · Access to Exchange Web Services (EWS) endpoint · Attacker-controlled URL for NTLM relaying
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106906

Scores

CVSS v3 8.1
EPSS 0.2380
EPSS Percentile 97.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (4)
microsoft/exchange_server 2010 sp3_rollup_26
microsoft/exchange_server 2013 cumulative_update_22
microsoft/exchange_server 2016 cumulative_update_12
microsoft/exchange_server 2019 cumulative_update_1
Published Mar 05, 2019
Tracked Since Feb 18, 2026