CVE-2023-21707: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.0986.042Patch KB5024296 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1118.026Patch KB5024296 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.00.1497.048Patch KB5024296 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.023Patch KB5024296
Event History
Frequently Asked Questions
What is CVE-2023-21707?
CVE-2023-21707 is a vulnerability that allows remote code execution in Microsoft Exchange Server.
How severe is CVE-2023-21707?
CVE-2023-21707 has a severity value of 8.8, which is considered high.
Which versions of Microsoft Exchange Server are affected by CVE-2023-21707?
CVE-2023-21707 affects Microsoft Exchange Server 2013 (Cumulative Update 23), 2016 (Cumulative Update 23), and 2019 (Cumulative Update 11 and 12).
How can I fix CVE-2023-21707?
To fix CVE-2023-21707, apply the corresponding cumulative update provided by Microsoft or follow the remediation steps provided in the official documentation.
Where can I find more information about CVE-2023-21707?
You can find more information about CVE-2023-21707 on the Microsoft Security Response Center website.