securityonline.info 9/1/2026, 2:41:56 AM · external

Exchange flaw lets attackers run code as SYSTEM via NTLM relay.

Exchange flaw lets attackers run code as SYSTEM via NTLM relay.
CyberSIXT Evidence Panel
Primary Source msrc.microsoft.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

A critical vulnerability in Microsoft Exchange Server, tracked as CVE-2026-62911, allows local unauthenticated attackers to achieve remote code execution with SYSTEM privileges. It affects various versions of Exchange Server 2016 and 2019, prompting immediate patch application via Microsoft updates. Demonstrated at Pwn2Own Berlin, the attack exploits the Mailbox Replication Proxy Service through NTLM relay techniques, posing significant risks to enterprise communications. Administrators are advised to apply specific KB updates and strengthen network defenses to prevent exploitation.

View Primary Source Via securityonline.info

Article by CyberSIXT