CVE-2023-21529

Published Feb 14, 2023

Last updated 12 days ago

Overview

Description
Microsoft Exchange Server Remote Code Execution Vulnerability
Source
secure@microsoft.com
NVD status
Analyzed
Products
exchange_server

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
Exploit added on
Apr 13, 2026
Exploit action due
Apr 27, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

secure@microsoft.com
CWE-502

Social media

Hype score
Not currently trending
  1. CISA added CVE-2023-21529 to KEV: authenticated deserialization → RCE on on-prem Exchange, and ransomware crews are using it. Microsoft patched in Feb 2023. If your Exchange box hasn't taken that update, this week. https://t.co/4yuOpRwcmN

    @TechTranslators

    25 Apr 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性カタログが更新。4件についてランサムウェアによる悪用を確認。対象はPaperCut NG/MFのCVE-2023-27351、TeamCityのCVE-2024-27199、Exchange Sevr

    @__kokumoto

    21 Apr 2026

    1024 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    1 Reply

    1 Quote

  3. 🛡️ Microsoft Exchange Deserialization RCE Explained CVE-2023-21529 is a critical vulnerability in Microsoft Exchange Server. It involves the deserialization of untrusted data, allowing an authenticated attacker to achieve remote code execution. This is a classic example of

    @xhackio

    14 Apr 2026

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🛡️ CVE-2023-21529: Vulnerabilidad Crítica de Deserialización en Microsoft Exchange Server Análisis técnico de CVE-2023-21529, una vulnerabilidad de deserialización en Microsoft Exchange Server que permite ejecución remota de código. Impacto, mitigaci https://t.co/LOXH

    @CiberPlanetaOrg

    14 Apr 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🛡️ Alerta de Seguridad: Vulnerabilidad de Deserialización de Datos No Confiables en Microsoft Exchange Server (CVE-2023-21529) Microsoft Exchange Server sufre una vulnerabilidad de deserialización de datos no confiables (CWE-502) que permite ejecución remota de código (R

    @CiberPlanetaOrg

    14 Apr 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. TRC analysis shows attackers chaining Microsoft Exchange Server deserialization exploits (CVE-2023-21529) with Windows privilege escalation vulnerabilities for lateral movement campaigns. Runtime segmentation helps contain post-compromise activity across cloud workloads.

    @aviatrixtrc

    14 Apr 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CISAが既知の悪用された脆弱性7件をカタログに追加 CISA Adds Seven Known Exploited Vulnerabilities to Catalog #CISA (Apr 13) CVE-2012-1854 Microsoft Visual Basic for Applications のライブラリ読み込みの脆弱性 CVE-2020-9715 Adobe AcrobatのUse-Af

    @foxbook

    13 Apr 2026

    285 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2023-21529 #Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability https://t.co/FOaSS8P5RM

    @ScyScan

    13 Apr 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations