Record summary

CVE-2023-36745 has a selected CVSS score of 8.0 (high); EIP currently links 1 repository PoC.

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

Description source: GitHub Advisory

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 24, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 26, 2025 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Microsoft Exchange Server 2016 Cumulative Update 23

Browse Microsoft / Microsoft Exchange Server 2016 Cumulative Update 23
CVE List15.01.0 to < 15.01.2507.032affected

Microsoft Exchange Server 2019 Cumulative Update 12

Browse Microsoft / Microsoft Exchange Server 2019 Cumulative Update 12
CVE List15.02.0 to < 15.02.1118.037affected

Microsoft Exchange Server 2019 Cumulative Update 13

Browse Microsoft / Microsoft Exchange Server 2019 Cumulative Update 13
CVE List15.02.0 to < 15.02.1258.025affected

Proofs of concept

1

Repository PoCs

GitHubN1k0la-T/CVE-2023-36745Repository PoCby N1k0la-TStars: 169Not analyzed35 files

676.7 KiB

GitHub

PoC details

References

2