Back

CVE-2019-1373

CRITICAL

A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'.

Published: Nov 12, 2019 Modified: Jun 17, 2026
CWE-502

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (5)

Vendor Product Version
microsoft exchange_server 2013
microsoft exchange_server 2016
microsoft exchange_server 2016
microsoft exchange_server 2019
microsoft exchange_server 2019

GitHub Security Advisory GHSA-24mr-37ph-25xf

A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 18.16%

Top 3% most likely to be exploited

Threat Score 44.6 / 100

Data Sources

NVD EPSS GitHub