CVE-2023-36439: Microsoft Exchange Server Remote Code Execution Vulnerability
Published Nov 14, 2023
·Updated
Microsoft Exchange Server Remote Code Execution Vulnerability
Affected Software
9 affected componentsFixes available
Microsoft Exchange Server 2016=23
Microsoft Exchange Server 2016=23
Microsoft Exchange Server 2019=12
Microsoft Exchange Server 2019=13
Microsoft Exchange Server 2019=12
Microsoft Exchange Server 2019=13
Microsoft Exchange Server=2016-cumulative_update_23
Microsoft Exchange Server=2019-cumulative_update_12
Microsoft Exchange Server=2019-cumulative_update_13
Remediation
Event History
Nov 14, 2023
CVE Published
08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·05:57 PM
Data Sourced
via MITRE·05:57 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2023-36439?
CVE-2023-36439 is a vulnerability in Microsoft Exchange Server that allows remote code execution.
2
How severe is CVE-2023-36439?
CVE-2023-36439 has a high severity rating of 8.
3
Which versions of Microsoft Exchange Server are affected by CVE-2023-36439?
The vulnerability affects Microsoft Exchange Server 2019 versions 12 and 13, as well as Microsoft Exchange Server 2016 version 23.
4
How can I fix CVE-2023-36439?
To fix CVE-2023-36439, you can apply the patches provided by Microsoft. For Microsoft Exchange Server 2019 versions 12 and 13, the patch can be downloaded from the Microsoft website. For Microsoft Exchange Server 2016 version 23, the patch is also available on the Microsoft website.
5
Where can I find more information about CVE-2023-36439?
You can find more information about CVE-2023-36439 on the Microsoft Security Response Center website.