CVE-2023-35388: Microsoft Exchange Server Remote Code Execution Vulnerability
Published Aug 8, 2023
·Updated
Microsoft Exchange Server Remote Code Execution Vulnerability
Affected Software
6 affected componentsFixes available
Microsoft Exchange Server=2016-cumulative_update_23
Microsoft Exchange Server=2019-cumulative_update_12
Microsoft Exchange Server=2019-cumulative_update_13
Microsoft Exchange Server 2019=12
15.02.1118.037
Microsoft Exchange Server 2019=13
15.02.1258.025
Microsoft Exchange Server 2016=23
15.01.2507.032
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1118.037Patch KB5030524 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.032Patch KB5030524 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1258.025Patch KB5030524
Event History
Aug 8, 2023
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Description
CVE Published
via MITRE·05:08 PM
Data Sourced
via MITRE·05:08 PM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-35388?
CVE-2023-35388 is a remote code execution vulnerability in Microsoft Exchange Server.
2
How severe is CVE-2023-35388?
CVE-2023-35388 has a severity rating of high.
3
Which versions of Microsoft Exchange Server are affected by CVE-2023-35388?
CVE-2023-35388 affects Microsoft Exchange Server 2016 cumulative update 23, Exchange Server 2019 cumulative update 12, and Exchange Server 2019 cumulative update 13.
4
How can I fix CVE-2023-35388?
You can fix CVE-2023-35388 by applying the security updates provided by Microsoft.