CVE-2023-21529: Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.
Other sources
Microsoft Exchange Server Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.021Patch KB5023038 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1118.025Patch KB5023038 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.0986.041Patch KB5023038 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.00.1497.047Patch KB5023038
Event History
Frequently Asked Questions
What is CVE-2023-21529?
CVE-2023-21529 is a vulnerability in Microsoft Exchange Server that allows remote code execution.
How severe is CVE-2023-21529?
CVE-2023-21529 has a severity level of 8.8, which is considered high.
Which versions of Microsoft Exchange Server are affected by CVE-2023-21529?
CVE-2023-21529 affects Microsoft Exchange Server 2013, 2016, and 2019 with specific cumulative updates.
How can I fix CVE-2023-21529?
To fix CVE-2023-21529, you need to apply the relevant cumulative update or patch provided by Microsoft.
Where can I find more information about CVE-2023-21529?
You can find more information about CVE-2023-21529 on the Microsoft Security Response Center's website.