CVE-2023-21745HighCVSS 8.0
Microsoft Exchange Server Spoofing Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability? An authenticated attacker could exploit this vulnerability LAN-side or potentially from the internet.
How could an attacker exploit this vulnerability? An authenticated attacker could achieve exploitation by using a PowerShell remoting session to the server.
🎯 Affected products3
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 11
- Microsoft Exchange Server 2019 Cumulative Update 12
✅ Remediation
KB5022143 (Security Update) — fixed build 15.01.2507.017 KB5022193 (Security Update) — fixed build 15.02.1118.021 KB5022193 (Security Update) — fixed build 15.02.0986.037
🔗 References (6)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21745
- patchhttps://www.microsoft.com/download/details.aspx?familyid=e775134a-a23b-4375-8be2-61123b4addd3
- referencehttps://support.microsoft.com/help/5022143
- patchhttps://www.microsoft.com/download/details.aspx?familyid=6237df2d-0ad0-415d-8b98-a8c985ed6214
- referencehttps://support.microsoft.com/help/5022193
- patchhttps://www.microsoft.com/download/details.aspx?familyid=ecb11461-88df-428b-b0a8-1fa9fa892b25