macc /
FR EN
Demander un échange
← Retour à la console
Critique CCB · Belgique CVE-2026-45504

Privilege Escalation Vulnerability in Exchange Server 2016, 2019 and …

Publié

Description

A specifically crafted attachment, with the ProviderEndpointUrl field pointing towards a malicious infrastructure is used for SSRF. When the attachment is opened, the Exchange Server sends a request to the malicious server which returns a modified URI containing the path to the desired file. An oversight in the processing logic causes the server to return the requested files to the attacker without validation. The root cause of the vulnerability is the lack of validation of values returned by WOPU providers, causing the server to respond to any request without additional checks.