🔘 Vulnerability(cybersecuritynews.com): Public PoC Released for Microsoft Exchange Server Pre-auth RCE Vulnerability
✉ 01.09.2026 14:28:53 Abinaya
💻 A public proof-of-concept exploit has been released for CVE-2026-62911, a Microsoft Exchange Server vulnerability linked to an authentication capture-and-replay weakness.
While Microsoft classifies the issue as an elevation-of-privilege flaw, the published research describes an attack chain that can lead to unauthenticated remote code execution and a SYSTEM-level compromise on vulnerable Exchange environments.
The PoC, published on GitHub by researcher Nguyen Van Hiep, targets the Exchange Mailbox Replication Proxy service, commonly known as MRSProxy.
The exploit documentation claims that a reachable HTTP. sys-hosted MRSProxy endpoint does not enforce Extended Protection for Authentication, enabling an attacker to relay NTLM authentication from an Exchange machine account to the service.
Microsoft disclosed CVE-2026-62911 in August 2026 as an authentication-bypass capture-replay issue affecting on-premises Microsoft Exchange Server.
Public PoC For Exchange Server Pre-Auth RCE
Microsoft’s public description states that an authorized attacker could elevate privileges over a network. In contrast, the available PoC increases practical risk by demonstrating an NTLM relay path that may eliminate the need for prior Exchange credentials in certain configurations.
According to the technical analysis, Exchange exposes MRSProxy through separate endpoints. Extended Protection protects the IIS-hosted /EWS/MRSProxy.svc path.
However, the HTTPsys-hosted MailboxReplicationService ProxyService endpoint may not validate channel bindings. This creates a relay opportunity where a captured machine-account authentication attempt can be forwarded to the vulnerable Exchange service.
The attack chain begins by coercing an Exchange server to authenticate to an attacker-controlled listener through a technique such as PetitPotam. The attacker can then relay the NTLM authentication to a second vulnerable Exchange server.
If the relay succeeds, the machine account is treated as authenticated by MRSProxy. It receives access to Exchange mailbox replication functionality.
The PoC reportedly abuses WCF methods within the replication service, including IMailbox_Config6 and IMailbox_Connect. The first method accepts a file path, while the second may cause Exchange to write content to that location...
#Cyber_Security_News #Microsoft #Vulnerability #cyber_security #cyber_security_news
https://cybersecuritynews.com/poc-microsoft-exchange-server-pre-auth-rce/
read it on CSN:
https://csn.net4me.net/cyber_security_27902.html

Cyber Security News
Public PoC Released for Microsoft Exchange Server Pre-auth RCE Vulnerability
Public PoC released for CVE-2026-62911, an Exchange Server authentication capture-and-replay flaw.
September 1, 2026 5