Microsoft Exchange Zero-Day Hack Confirmed—3 Vulnerabilities Exploited

TL;DR AI
2 min readKey summary
At Pwn2Own Berlin, researchers chained three previously unknown Microsoft Exchange flaws to achieve SYSTEM-level remote code execution.
The DEVCORE Research Team, including Orange Tsai, disclosed the exploit details and received a $200,000 award.
The case highlights how multiple zero-days can fully compromise a widely used email server and why fast patching matters.
It also underscores the importance of coordinated vulnerability disclosure through programs like Pwn2Own and ZDI.



