CVE-2023-21707
HIGHMicrosoft Exchange Server - Remote Code Execution via Untrusted Data Deserialization
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-21707. PoCs published by N1k0la-T.
AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2023-21707, a deserialization vulnerability in Microsoft Exchange. The exploit leverages a crafted payload to achieve remote code execution by manipulating serialized objects and using a custom serialization binder to bypass type checks.
Description
Microsoft Exchange Server Remote Code Execution Vulnerability
Exploits (1)
This repository contains a proof-of-concept exploit for CVE-2023-21707, a deserialization vulnerability in Microsoft Exchange. The exploit leverages a crafted payload to achieve remote code execution by manipulating serialized objects and using a custom serialization binder to bypass type checks.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H