Double free in Microsoft Exchange Server - CVE-2026-55007
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a double free in Microsoft Exchange Server when processing a specially crafted Visio attachment during content indexing. A remote attacker can send a specially crafted Visio attachment to an affected Exchange server to execute arbitrary code.
Successful exploitation requires the target system to be under sustained low-memory conditions.