Description
Microsoft Exchange Server Spoofing Vulnerability
In plain language
AI Worth attentionBusinesses using the listed Microsoft Exchange Server updates should schedule the available security update soon to prevent an attacker from impersonating trusted communications or taking control of email services.
CWE-502 deserialization weakness in Microsoft Exchange Server, reachable from an adjacent network by an attacker with low privileges, with high potential confidentiality, integrity, and availability impact.
What to do now
- Check whether your Microsoft Exchange Server is Exchange Server 2016 CU23 or Exchange Server 2019 CU12 or CU13, and record its current build number.
- Update Exchange Server 2016 CU23 to build 15.01.2507.032.
- Update Exchange Server 2019 CU12 to build 15.02.1118.037 or Exchange Server 2019 CU13 to build 15.02.1258.025.
- Have IT confirm the update installed successfully and investigate unexpected mailbox, account, or mail-flow changes.
CVSS Vector Breakdown
AV:AAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2023-36757 and every CVE in our database. Create a free account — no credit card required.
Create Free Account