Microsoft Exchange Server Spoofing Vulnerability
CVE-2023-21762
Summary
A spoofing vulnerability exists in Microsoft Exchange Server, potentially allowing an attacker to impersonate another user and send malicious emails without proper authentication. This can facilitate phishing attacks, where the recipient may be misled into believing they are receiving legitimate communication. Organizations using affected versions of Exchange Server should apply security updates promptly to mitigate the risk of exploitation. For further details, refer to Microsoft's advisory.
Affected Version(s)
Microsoft Exchange Server 2013 Cumulative Update 23 x64-based Systems 15.00.0 < 15.00.1497.045
Microsoft Exchange Server 2016 Cumulative Update 23 x64-based Systems 15.01.0 < 15.01.2507.017
Microsoft Exchange Server 2019 Cumulative Update 11 x64-based Systems 15.02.0 < 15.02.0986.037
Get notified when SecurityVulnerability.io launches alerting 🔔
Well keep you posted 📧
News Articles
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 📰
First article discovered by BornCity
Vulnerability published
Vulnerability Reserved