CVE-2023-21529

9.5 CISA KEV

Microsoft · Exchange Server

A remote code execution vulnerability in Microsoft Exchange Server allows authenticated attackers to execute arbitrary code via insecure deserialization of untrusted data.

Executive summary

This critical remote code execution vulnerability in Microsoft Exchange Server is being actively exploited in the wild and poses a severe threat to organizational data and system integrity.

Vulnerability

The flaw is a deserialization of untrusted data (CWE-502) vulnerability that enables an authenticated attacker with network access to execute arbitrary code on the underlying server, potentially with SYSTEM level privileges. The attack vector is of low complexity and requires no user interaction, making it highly dangerous for enterprise environments.

Business impact

Successful exploitation of this vulnerability allows for full system compromise, granting an attacker the ability to execute arbitrary code on the affected Exchange Server. Given the critical 9.5 CVSS score and confirmed use in ransomware campaigns, the risk includes total loss of confidentiality, integrity, and availability of email infrastructure and sensitive internal data. The inclusion of this vulnerability in the CISA Known Exploited Vulnerabilities catalog underscores the immediate necessity for remediation.

Remediation

Immediate Action: Apply the February 2023 security updates, specifically KB5023038, to all vulnerable Exchange Server instances immediately.

Proactive Monitoring: Review server logs for suspicious process spawning, unusual PowerShell activity, or unauthorized attempts to access sensitive deserialization endpoints.

Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to inspect and block malicious serialized objects, though patching remains the only definitive resolution.

Exploitation status

Public Exploit Available: Yes, public proof of concept exploits are available.

Analyst recommendation

Due to the critical nature of this vulnerability and its active use by ransomware groups, organizations must prioritize patching all Exchange Servers. Delaying remediation significantly increases the risk of complete domain compromise and data exfiltration. Apply the vendor provided security updates as the primary and most urgent action.

More Microsoft CVEs

Sources