CVE-2019-0586
published 2019-01-08CVE-2019-0586: A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft…
PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
15.40%
96.4th percentile
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | microsoft_exchange_server | — | — |
| microsoft | microsoft_exchange_server | — | — |
| microsoft | microsoft_exchange_server | — | — |
| msrc | microsoft_exchange_server_2010_service_pack_3 | — | — |
| msrc | microsoft_exchange_server_2013_cumulative_update_21 | — | — |
| msrc | microsoft_exchange_server_2013_cumulative_update_22 | — | — |
| msrc | microsoft_exchange_server_2013_cumulative_update_23 | — | — |
| msrc | microsoft_exchange_server_2013_service_pack_1 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_10 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_11 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_12 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_13 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_14 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_15 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_16 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_17 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_18 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_19 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_8 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_9 | — | — |
| msrc | microsoft_exchange_server_2019 | — | — |
| msrc | microsoft_exchange_server_2019_cumulative_update_1 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploitation vector is a specially crafted email sent to a vulnerable Exchange server; inspect inbound SMTP traffic for malformed/oversized email objects targeting Exchange memory handling routines. ↗
- →If exploited, attacker code runs as SYSTEM on the Exchange server; monitor for unexpected processes, account creation, or privilege escalation originating from Exchange worker processes (e.g., w3wp.exe, EdgeTransport.exe). ↗
- ·Exploit status at time of advisory was 'Exploitation More Likely' for both latest and older software releases, but no public exploit or active exploitation was confirmed; detection posture should remain elevated. ↗
- ·The vulnerability is a memory corruption flaw in Microsoft Exchange's object handling; patching via KB4471389 and associated update packages is the primary remediation. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc9.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Exchange Server Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 7.8
CVE-2021-26857 [CRITICAL] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
FAQ: Is this vulnerability being used in an active attack?
Yes. The vulnerability described in this CVE is one of four vulnerabilities that are being exploited in an active attack. The security updates address this attack. More information can be found here: https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server.
What is the target for this attack?
The initial attack in this attack chain targets an Exchange On-prem server that is able to receive untrusted connections from an external source. In addition, the Exchange server would need to be running Microsoft Exchange Server 2013, 2016, or 2019.
Where can I get more information about how to protect myself from the vulnerabilities?
Pleas
Microsoft
Microsoft Exchange Server Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 9.1
CVE-2021-26855 [CRITICAL] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
FAQ: Is this vulnerability being used in an active attack?
Yes. The vulnerability described in this CVE is one of four vulnerabilities that are being exploited in an active attack. The security updates address this attack. More information can be found here: https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server.
What is the target for this attack?
The initial attack in this attack chain targets an Exchange On-prem server that is able to receive untrusted connections from an external source. In addition, the Exchange server would need to be running Microsoft Exchange Server 2013, 2016, or 2019.
Where can I get more information about how to protect myself from the vulnerabilities?
Pleas
Microsoft
Microsoft Exchange Server Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 7.8
CVE-2021-27065 [CRITICAL] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
FAQ: Is this vulnerability being used in an active attack?
Yes. The vulnerability described in this CVE is one of four vulnerabilities that are being exploited in an active attack. The security updates address this attack. More information can be found here: https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server.
What is the target for this attack?
The initial attack in this attack chain targets an Exchange On-prem server that is able to receive untrusted connections from an external source. In addition, the Exchange server would need to be running Microsoft Exchange Server 2013, 2016, or 2019.
Where can I get more information about how to protect myself from the vulnerabilities?
Pleas
Microsoft
Microsoft Exchange Server Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 7.8
CVE-2021-26858 [CRITICAL] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
FAQ: Is this vulnerability being used in an active attack?
Yes. The vulnerability described in this CVE is one of four vulnerabilities that are being exploited in an active attack. The security updates address this attack. More information can be found here: https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server.
What is the target for this attack?
The initial attack in this attack chain targets an Exchange On-prem server that is able to receive untrusted connections from an external source. In addition, the Exchange server would need to be running Microsoft Exchange Server 2013, 2016, or 2019.
Where can I get more information about how to protect myself from the vulnerabilities?
Pleas
Microsoft
Microsoft Exchange Memory Corruption Vulnerability
vendor_msrc·2019-01-08·CVSS 9.8
CVE-2019-0586 [CRITICAL] Microsoft Exchange Memory Corruption Vulnerability
Microsoft Exchange Memory Corruption Vulnerability
Description: A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. An attacker could then install programs; view, change, or delete data; or create new accounts.
Exploitation of the vulnerability requires that a specially crafted email be sent to a vulnerable Exchange server.
The security update addresses the vulnerability by correcting how Microsoft Exchange handles objects in memory.
Microsoft Exchange Server: Microsoft Exchange Server
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Relea
GHSA
GHSA-qmqc-fwpv-mx4f: A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microso
ghsa_unreviewed·2022-05-13
CVE-2019-0586 [CRITICAL] CWE-787 GHSA-qmqc-fwpv-mx4f: A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microso
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.
No detection rules found.
No public exploits indexed.
Trendmicro
January Patch Tuesday Contains Fixes for DHCP
blogs_trendmicro·2019-01-09·CVSS 9.8
[CRITICAL] January Patch Tuesday Contains Fixes for DHCP
Sfruttamento vulnerabilità
## January Patch Tuesday Contains Fixes for DHCP
Microsoft starts off 2019 relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
By: Trend Micro Research Jan 09, 2019 Read time: ( words)
Save to Folio
In the last few months of 2018, Microsoft’s regular security releases included patches for vulnerabilities that were actively being exploited . Thankfully, 2019 started off relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
The most notable
Trendmicro
January Patch Tuesday Contains Fixes for DHCP
blogs_trendmicro·2019-01-09·CVSS 9.8
[CRITICAL] January Patch Tuesday Contains Fixes for DHCP
Exploits & Vulnerabilities
## January Patch Tuesday Contains Fixes for DHCP
Microsoft starts off 2019 relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
By: Trend Micro Research Jan 09, 2019 Read time: ( words)
Save to Folio
In the last few months of 2018, Microsoft’s regular security releases included patches for vulnerabilities that were actively being exploited . Thankfully, 2019 started off relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
The most notable
Trendmicro
January Patch Tuesday Contains Fixes for DHCP
blogs_trendmicro·2019-01-09·CVSS 9.8
[CRITICAL] January Patch Tuesday Contains Fixes for DHCP
Ausnutzung von Schwachstellen
## January Patch Tuesday Contains Fixes for DHCP
Microsoft starts off 2019 relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
By: Trend Micro Research Jan 09, 2019 Read time: ( words)
Save to Folio
In the last few months of 2018, Microsoft’s regular security releases included patches for vulnerabilities that were actively being exploited . Thankfully, 2019 started off relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
The most notab
Trendmicro
January Patch Tuesday Contains Fixes for DHCP
blogs_trendmicro·2019-01-09·CVSS 9.8
[CRITICAL] January Patch Tuesday Contains Fixes for DHCP
Exploits & Vulnerabilities
## January Patch Tuesday Contains Fixes for DHCP
Microsoft starts off 2019 relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
By: Trend Micro Research 2019/01/09 Read time: ( words)
Save to Folio
In the last few months of 2018, Microsoft’s regular security releases included patches for vulnerabilities that were actively being exploited . Thankfully, 2019 started off relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
The most notable of
Trendmicro
January Patch Tuesday Contains Fixes for DHCP
blogs_trendmicro·2019-01-09·CVSS 9.8
[CRITICAL] January Patch Tuesday Contains Fixes for DHCP
Exploits y vulnerabilidades
## January Patch Tuesday Contains Fixes for DHCP
Microsoft starts off 2019 relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
By: Trend Micro Research Jan 09, 2019 Read time: ( words)
Save to Folio
In the last few months of 2018, Microsoft’s regular security releases included patches for vulnerabilities that were actively being exploited . Thankfully, 2019 started off relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
The most notable
Trendmicro
January Patch Tuesday Contains Fixes for DHCP
blogs_trendmicro·2019-01-09·CVSS 9.8
[CRITICAL] January Patch Tuesday Contains Fixes for DHCP
Exploits & Vulnerabilities
# January Patch Tuesday Contains Fixes for DHCP
Microsoft starts off 2019 relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
By: Trend Micro Research
Jan 09, 2019
Read time: ( words)
Save to Folio
In the last few months of 2018, Microsoft’s regular security releases included patches for vulnerabilities that were actively being exploited. Thankfully, 2019 started off relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
The most notable o
Trendmicro
January Patch Tuesday Contains Fixes for DHCP
blogs_trendmicro·2019-01-09·CVSS 9.8
[CRITICAL] January Patch Tuesday Contains Fixes for DHCP
Exploits & Vulnerabilities
# January Patch Tuesday Contains Fixes for DHCP
Microsoft starts off 2019 relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
By: Trend Micro Research
2019/01/09
Read time: ( words)
Save to Folio
In the last few months of 2018, Microsoft’s regular security releases included patches for vulnerabilities that were actively being exploited. Thankfully, 2019 started off relatively smoothly with 49 security patches and two advisories — seven of these vulnerabilities were rated Critical and 40 were Important. Ten of these were disclosed through the Zero Day Initiative (ZDI) program.
The most notable of
2019-01-08
Published