← Back to browse · API

CVE-2023-21529

Severity
HIGH
CVSS
8.8
EPSS
0.62104
Risk score
81.94
CISA KEV
Yes
PoC
No
Published
2026-04-13
Modified
2026-04-13
First seen
2026-08-07
Aliases
EUVD-2023-25697, GHSA-HJXR-GV9H-RJXC
Products
Microsoft:Exchange Server, Microsoft:Microsoft Exchange Server 2013 Cumulative Update 23 15.00.0 <15.00.1497.047, Microsoft:Microsoft Exchange Server 2016 Cumulative Update 23 15.01.0 <15.01.2507.021, Microsoft:Microsoft Exchange Server 2019 Cumulative Update 11 15.02.0 <15.02.0986.041, Microsoft:Microsoft Exchange Server 2019 Cumulative Update 12 15.02.0 <15.02.1118.025
Sources
euvd EUVD-2023-25697
cisa.gov CVE-2023-21529

Description

Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.

References