Description
Microsoft Exchange Server Remote Code Execution Vulnerability
In plain language
AI Act nowCVE-2023-21529 is a Microsoft Exchange Server weakness where a low-privilege attacker can remotely take full control of your server and run malicious code; if you run the listed Exchange versions, you should act immediately because it has been used in ransomware campaigns.
CVE-2023-21529 is an authenticated, network-reachable remote code execution issue (CWE-502) in Microsoft Exchange Server that allows attackers with low privileges to manipulate untrusted data loading so the server runs arbitrary code, enabling full takeover; it’s been listed by CISA as used in ransomware activity.
What to do now
- Check your Microsoft Exchange Server version and cumulative update level, and confirm whether you are on one of: Exchange Server 2013 CU23, Exchange Server 2016 CU23, Exchange Server 2019 CU11, or Exchange Server 2019 CU12.
- If you match one of those affected versions, plan an urgent update to the fixed versions: Exchange Server 2013 CU23 → 15.00.1497.047, Exchange Server 2016 CU23 → 15.01.2507.021, Exchange Server 2019 CU11 → 15.02.0986.041, Exchange Server 2019 CU12 → 15.02.1118.025.
- After updating, verify the installed patch level matches the fixed version and that services (including mail flow) are functioning normally.
- If you cannot patch immediately, apply the vendor mitigations described by Microsoft for CVE-2023-21529 and follow CISA guidance for ransomware-impacted guidance; otherwise, restrict/discontinue use if mitigations are unavailable.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2023-21529 and every CVE in our database. Create a free account — no credit card required.
Create Free Account