Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-28310
Key Information:
- Vendor
- Microsoft
- Status
- Vendor
- CVE Published:
- 14 June 2023
Badges
Summary
A remote code execution vulnerability in Microsoft Exchange Server allows an attacker to execute arbitrary code on the affected server. Exploitation of this vulnerability can lead to unauthorized access, data compromise, and potential disruption of services. It is critical for administrators to apply the necessary patches and updates to mitigate risks associated with this security flaw.
Affected Version(s)
Microsoft Exchange Server 2016 Cumulative Update 23 x64-based Systems 15.01.0 < 15.01.2507.027
Microsoft Exchange Server 2019 Cumulative Update 12 x64-based Systems 15.02.0 < 15.02.1118.030
Microsoft Exchange Server 2019 Cumulative Update 13 x64-based Systems 15.02.0 < 15.02.1258.016
News Articles
References
EPSS Score
14% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- đź“°
First article discovered by Krebs on Security
Vulnerability published
Vulnerability Reserved