VendorsMicrosoftexchange_serverall versions
Vulnerabilities

Microsoft Exchange Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

259CVEs
CVE-2021-34473
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-07-14 · Analyzed
10.0KEVEPSS 1.000
CVE-2021-28480
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-04-13 · Modified
10.0EPSS 0.712
CVE-2007-0213
Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.
Published 2007-05-08 · Modified
10.01 PoCEPSS 0.662
CVE-2004-0574
The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.
Published 2004-10-16 · Modified
10.01 PoCEPSS 0.644
CVE-2021-28481
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-04-13 · Modified
10.0EPSS 0.362
CVE-2004-0840
The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.
Published 2004-10-16 · Modified
10.0EPSS 0.303
CVE-2018-8302
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.
Published 2018-08-15 · Modified
10.0EPSS 0.255
CVE-2018-8154
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8151.
Published 2018-05-09 · Modified
10.0EPSS 0.241
CVE-1999-0385
The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.
Published 1999-09-29 · Modified
10.0EPSS 0.182
CVE-2019-0586
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.
Published 2019-01-08 · Modified
10.0EPSS 0.154
CVE-2021-26855
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-03-02 · Analyzed
9.8KEV4 PoCEPSS 1.000
CVE-2021-34523
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2021-07-14 · Analyzed
9.8KEVEPSS 1.000
CVE-2022-41080
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2022-11-09 · Analyzed
9.8KEVEPSS 0.773
CVE-2019-1373
A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'.
Published 2019-11-12 · Modified
9.8EPSS 0.214
CVE-2024-21410
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2024-02-13 · Analyzed
9.8KEVEPSS 0.126
CVE-2023-21709
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2023-08-08 · Modified
9.8EPSS 0.020
CVE-2021-26427
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-10-13 · Modified
9.6EPSS 0.009
CVE-2026-55008
Microsoft Exchange Server Spoofing Vulnerability
Published 2026-07-14 · Analyzed
9.6EPSS 0.009
CVE-2017-8540
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8541.
Published 2017-05-26 · Analyzed
9.3KEV1 PoCEPSS 0.719
CVE-2018-0986
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection, Microsoft Security Essentials, Microsoft System Center Endpoint Protection, Microsoft Exchange Server, Microsoft System Center, Microsoft Forefront Endpoint Protection.
Published 2018-04-04 · Modified
9.31 PoCEPSS 0.633
CVE-2017-8538
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8540 and CVE-2017-8541.
Published 2017-05-26 · Modified
9.31 PoCEPSS 0.500
CVE-2017-8541
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8540.
Published 2017-05-26 · Modified
9.31 PoCEPSS 0.481
CVE-2017-11937
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to remote code execution. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".
Published 2017-12-07 · Modified
9.3EPSS 0.283
CVE-2009-0098
Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."
Published 2009-02-10 · Modified
9.3EPSS 0.249
CVE-2019-0724
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0686.
Published 2019-03-06 · Modified
9.3EPSS 0.238
CVE-2017-11940
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to remote code execution. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability". This is different than CVE-2017-11937.
Published 2017-12-08 · Modified
9.3EPSS 0.198
CVE-2018-8265
A remote code execution vulnerability exists in the way Microsoft Exchange software parses specially crafted email messages, aka "Microsoft Exchange Remote Code Execution Vulnerability." This affects Microsoft Exchange Server.
Published 2018-10-10 · Modified
9.3EPSS 0.193
CVE-2009-1491
McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, and possibly other anti-virus or anti-spam products from McAfee or other vendors, does not scan X- headers for malicious content, which allows remote attackers to bypass virus detection via a crafted message, as demonstrated by a message with an X-Testing header and no message body.
Published 2009-05-05 · Modified
9.3EPSS 0.028
CVE-2020-17132
Microsoft Exchange Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.1EPSS 0.899
CVE-2021-26412
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-03-02 · Modified
9.1EPSS 0.338
CVE-2021-27078
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-03-02 · Modified
9.1EPSS 0.216
CVE-2020-17142
Microsoft Exchange Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.1EPSS 0.034
CVE-2026-69641
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
9.1EPSS 0.008
CVE-2020-0688
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
Published 2020-02-11 · Analyzed
9.0KEV2 PoCEPSS 1.000
CVE-2021-28482
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-04-13 · Modified
9.0EPSS 0.832
CVE-2020-17117
Microsoft Exchange Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.0EPSS 0.489
CVE-2020-16875
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
9.0EPSS 0.474
CVE-2020-17084
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2020-11-11 · Modified
9.0EPSS 0.039
CVE-2021-28483
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-04-13 · Modified
9.0EPSS 0.012
CVE-2022-21969
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.011
1 / 7Next →