Record summary

CVE-2023-36757 has a selected CVSS score of 8.0 (high).

Description

Microsoft Exchange Server Spoofing Vulnerability

Description source: GitHub Advisory

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 26, 2025 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Microsoft Exchange Server 2016 Cumulative Update 23

Browse Microsoft / Microsoft Exchange Server 2016 Cumulative Update 23
CVE List15.01.0 to < 15.01.2507.032affected

Microsoft Exchange Server 2019 Cumulative Update 12

Browse Microsoft / Microsoft Exchange Server 2019 Cumulative Update 12
CVE List15.02.0 to < 15.02.1118.037affected

Microsoft Exchange Server 2019 Cumulative Update 13

Browse Microsoft / Microsoft Exchange Server 2019 Cumulative Update 13
CVE List15.02.0 to < 15.02.1258.025affected

References

2