CVE-2023-21709: Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1258.025Patch KB5030524 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.032Patch KB5030524 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1118.037Patch KB5030524
Event History
Frequently Asked Questions
What is CVE-2023-21709?
CVE-2023-21709 is a Microsoft Exchange Server Elevation of Privilege vulnerability.
How severe is CVE-2023-21709?
CVE-2023-21709 has a severity rating of 9.8 (Critical).
Which versions of Microsoft Exchange Server are affected by CVE-2023-21709?
CVE-2023-21709 affects Microsoft Exchange Server 2016 (versions 23), Microsoft Exchange Server 2019 (versions 12 and 13).
How can I fix CVE-2023-21709?
To fix CVE-2023-21709, you can apply the patch provided by Microsoft in the following links: Exchange Server 2016 (https://www.microsoft.com/download/details.aspx?familyid=026d6264-dc26-4482-aad7-c7f8e250e872), Exchange Server 2019 (https://www.microsoft.com/download/details.aspx?familyid=5ffd5bed-1305-4505-b21a-caf4913d03da).
Where can I find more information about CVE-2023-21709?
You can find more information about CVE-2023-21709 on the Microsoft Security Response Center website: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21709.