Record summary

CVE-2023-21707 has a selected CVSS score of 8.8 (high).

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

Description source: GitHub Advisory

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 28, 2025 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus

Microsoft Exchange Server 2013 Cumulative Update 23

Browse Microsoft / Microsoft Exchange Server 2013 Cumulative Update 23
CVE List15.00.0 to < 15.00.1497.048affected

Microsoft Exchange Server 2016 Cumulative Update 23

Browse Microsoft / Microsoft Exchange Server 2016 Cumulative Update 23
CVE List15.01.0 to < 15.01.2507.023affected

Microsoft Exchange Server 2019 Cumulative Update 11

Browse Microsoft / Microsoft Exchange Server 2019 Cumulative Update 11
CVE List15.02.0 to < 15.02.0986.042affected

Microsoft Exchange Server 2019 Cumulative Update 12

Browse Microsoft / Microsoft Exchange Server 2019 Cumulative Update 12
CVE List15.02.0 to < 15.02.1118.026affected

References

2