CVE-2023-36439HighCVSS 8.0

Microsoft Exchange Server Remote Code Execution Vulnerability

Published
November 14, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? For the vulnerability to be exploited, the attacker would need to be authenticated as a valid exchange user.

What privileges could be gained by an attacker who successfully exploited the vulnerability? An authenticated attacker could gain remote code execution rights on the server mailbox backend as NT AUTHORITY\SYSTEM.

According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability? An authenticated attacker could exploit this vulnerability with LAN access.

Are there any more actions I need to take to be protected from this vulnerability? Yes. Customers running an affected version of Microsoft Exchange need to download the November 2023 Security Update and ensure the Serialized Data Signing feature is enabled to be protected from this vulnerability. Disabling certificate signing of Powershell serialization payloads makes your server vulnerable to known Exchange vulnerabilities and weakens protection against unknown threats. We recommend leaving this feature enabled.

🎯 Affected products3

  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server 2019 Cumulative Update 12
  • Microsoft Exchange Server 2019 Cumulative Update 13

✅ Remediation

KB5032147 (Security Update) — fixed build 15.01.2507.035 KB5032146 (Security Update) — fixed build 15.02.1258.028 KB5032146 (Security Update) — fixed build 15.02.1118.040

🔗 References (6)