CVE-2019-0586 is a critical remote code execution vulnerability affecting Microsoft Exchange Server, stemming from improper memory handling. With a CVSS score of 9.8, it allows unauthenticated attackers to execute arbitrary code remotely with high impact on confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog, its high FAUCET Risk Score of 94/100 and notable community discussion suggest significant attention. There are no public exploit codes available in Metasploit, Nuclei, or ExploitDB, and it is not on the CISA Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_10:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_11:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2019:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.