CVE-2023-21761: Microsoft Exchange Server Information Disclosure Vulnerability
Microsoft Exchange Server Information Disclosure Vulnerability
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-21761?
CVE-2023-21761 is a vulnerability in Microsoft Exchange Server that allows for information disclosure.
What is the severity of CVE-2023-21761?
CVE-2023-21761 has a severity rating of 7.5, which is considered high.
Which versions of Microsoft Exchange Server are affected by CVE-2023-21761?
Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 11, and Microsoft Exchange Server 2019 Cumulative Update 12 are affected by CVE-2023-21761.
How can I fix CVE-2023-21761?
To fix CVE-2023-21761, you can apply the patches provided by Microsoft, which are available at the following URLs: Microsoft Exchange Server 2016 - Cumulative Update 23 (https://www.microsoft.com/downloads/details.aspx?familyid=e775134a-a23b-4375-8be2-61123b4addd3) and Microsoft Exchange Server 2019 - Cumulative Update 11 (https://www.microsoft.com/downloads/details.aspx?familyid=ecb11461-88df-428b-b0a8-1fa9fa892b25) or Cumulative Update 12 (https://www.microsoft.com/downloads/details.aspx?familyid=6237df2d-0ad0-415d-8b98-a8c985ed6214).
Where can I find more information about CVE-2023-21761?
You can find more information about CVE-2023-21761 on the Microsoft Security Response Center website at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21761.