CVE-2019-1373

CRITICAL

Microsoft Exchange - RCE

Title source: llm

Description

A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'.

Scores

CVSS v3 9.8
EPSS 0.0962
EPSS Percentile 92.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (5)

microsoft/exchange_server
microsoft/exchange_server
microsoft/exchange_server
microsoft/exchange_server
microsoft/exchange_server

Timeline

Published Nov 12, 2019
Tracked Since Feb 18, 2026