CVE-2023-21762
📛 CVE Title
Microsoft Exchange Server Spoofing Vulnerability
Description
Microsoft Exchange Server Spoofing Vulnerability
Overview
- State
- PUBLISHED
- Assigner (CNA)
- microsoft
- CVSS severity
- HIGH
- CVSS score
- 8.0 / 10
- CVSS vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C- Effective score
- 8.0 / 10 HIGH source: CNA overview
- MSRC score
- 8.0 / 10 HIGH MS rating: Important · Spoofing
- CWE(s)
-
CWE-502 - Reserved
- 2022-12-13
- Published
- 2023-01-10 08:00 UTC
- Last updated
- 2023-01-10 08:00 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/21xxx/CVE-2023-21762.json
- Linked Threat
- CVE-2023-21762 — Microsoft Exchange Server Spoofing Vulnerability
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2023-25929 - Assigner
- microsoft
- Published
- Jan 10, 2023, 12:00:00 AM
- Updated
- Feb 28, 2025, 9:14:23 PM
- EUVD base score (CVSS 3.1)
-
8.0 / 10
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - EUVD-reported EPSS
- 0.3900
- Vendors
- Microsoft
- Products
-
Microsoft Exchange Server 2019 Cumulative Update 12 (15.02.0 <15.02.1118.021)Microsoft Exchange Server 2019 Cumulative Update 11 (15.02.0 <15.02.0986.037)Microsoft Exchange Server 2013 Cumulative Update 23 (15.00.0 <15.00.1497.045)Microsoft Exchange Server 2016 Cumulative Update 23 (15.01.0 <15.01.2507.017)
- Aliases
-
GHSA-r79h-xwx8-4h7h
ENISA description: Microsoft Exchange Server Spoofing Vulnerability
EUVD references (1)
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-08-12 01:00 UTC (source: CVRF).
- MS severity
- Important
- Impact
- Spoofing
- MS CVSS base score
- 8.0 / 10 (temporal 7.0)
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - Exploit assessment
- Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
- Release
- 2023-Jan
Microsoft remediations / KB articles (6)
- 5022143 — Vendor Fix / Security Update (fixed build 15.01.2507.017)
- 5022143 — Update
- 5022193 — Vendor Fix / Security Update (fixed build 15.02.1118.021)
- 5022193 — Update
- 5022193 — Vendor Fix / Security Update (fixed build 15.02.0986.037)
- 5022188 — Vendor Fix / Security Update (fixed build 15.00.1497.045)
Microsoft FAQ (4)
According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability?
This vulnerability's attack is limited at the protocol level to a logically adjacent topology. This means it cannot simply be done across the internet, but instead needs something specific tied to the target. Good examples would include the same shared physical network (such as Bluetooth or IEEE 802.11), logical network (local IP subnet), or from within a secure or otherwise limited administrative domain (MPLS, secure VPN to an administrative network zone). This is common to many attacks that require machine-in-the-middle (MITM) type setups or that rely on initially gaining a foothold in another environment.
According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of availability (A:H)? What does that mean for this vulnerability?
If the attack is successful it could lead to a NTLM relay allowing for controls that would be able to block availability of a resource.
According to the CVSS metric, privileges required is low (PR:L). Does the attacker need to be in an authenticated role on the Exchange Server?
Yes, the attacker must be authenticated.
What type of information could be disclosed by this vulnerability?
Exploiting this vulnerability could allow the disclosure of NTLM hashes.
Affected products (4)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 |
15.01.0 (affected)
|
x64-based Systems |
| Microsoft | Microsoft Exchange Server 2019 Cumulative Update 12 |
15.02.0 (affected)
|
x64-based Systems |
| Microsoft | Microsoft Exchange Server 2019 Cumulative Update 11 |
15.02.0 (affected)
|
x64-based Systems |
| Microsoft | Microsoft Exchange Server 2013 Cumulative Update 23 |
15.00.0 (affected)
|
x64-based Systems |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- Microsoft Exchange Server Spoofing Vulnerability vendor-advisory
Web references (13)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- 5022193 msrc
- MSRC update guide: CVE-2023-21762 msrc
- 5022188 msrc
- 5022143 msrc
- 5022193 msrc
- https://support.microsoft.com/en-us/help/5022143 rapid7:support.microsoft.com
- https://support.microsoft.com/en-us/help/5022193 rapid7:support.microsoft.com
- https://support.microsoft.com/en-us/help/5022188 rapid7:support.microsoft.com
- https://support.microsoft.com/help/5022143 rapid7:support.microsoft.com
- https://attackerkb.com/topics/CVE-2023-21762 rapid7:attackerkb.com
- http://cwe.mitre.org/data/definitions/502.html rapid7:cwe.mitre.org
- https://support.microsoft.com/help/5022193 rapid7:support.microsoft.com
- https://www.cve.org/CVERecord?id=CVE-2023-21762 rapid7:www.cve.org
Remediations (18)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
rapid7
msft-kb5022188-6f3efecc-5cbb-42b0-adb6-32a217f34bb1
2026-05-28 22:59 UTC -
web:www.manageengine.com
Unfold what this Patch Tuesday has in store for you Patch Tuesday, the unofficial term for Microsoft's scheduled security fix release on every second Tuesday of a month, has been a constant topic of discussion ever since its inception. Upcoming Webinar May 14,2026 11:30 EDT & 6:30 a.m. GMT Agenda of the Free Patch Tuesday webinar A complete breakdown of all the latest Patch Tuesday updates ...
2026-06-04 10:14 UTC -
web:gemini.google.com
Get assistance with writing, planning, learning, and more from Google AI.
2026-06-04 10:14 UTC -
web:krebsonsecurity.com
Microsoft today pushed updates to fix at least 56 security flaws in its Windows operating systems and supported software. This final Patch Tuesday of 2025 tackles one zero-day bug that is already ...
2026-06-04 10:14 UTC -
web:msrc.microsoft.com
Access Microsoft Security Response Center's guide to address vulnerabilities, manage security risks, and keep your systems protected with the latest updates.
2026-06-04 10:14 UTC -
web:www.rapid7.com
Microsoft is publishing 137 vulnerabilities on May 2026 Patch Tuesday, including critical RCE in Netlogon and the Windows DNS client.
2026-06-04 10:14 UTC -
web:www.rapid7.com
Microsoft is publishing 66 new vulnerabilities today, which is far fewer than we've come to expect in recent months. However, the lone zero-day vulnerability this month demands attention.
2026-06-04 10:14 UTC -
web:nvd.nist.gov
The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics. For ...
2026-06-04 10:14 UTC -
web:www.notebookcheck.net
Microsoft's March 2026 Patch Tuesday fixes 79 flaws, including two publicly disclosed zero-days. Windows 11 gets KB5079473 and KB5078883, while Windows 10 receives KB5078885.
2026-05-22 05:46 UTC -
web:www.pcworld.com
Microsoft has released an emergency update for Windows 11. Update KB5086672 is an out-of-band update intended to resolve issues caused by the optional Windows update KB5079391 from late March ...
2026-05-22 05:46 UTC -
web:blog.qualys.com
Microsoft has rolled out its March 2026 Patch Tuesday updates, delivering a fresh batch of security fixes designed to keep Windows environments protected from emerging threats.
2026-05-22 05:46 UTC -
web:www.windowslatest.com
Windows 11 March 2026 Patch Tuesday update adds Emoji 16.0, Sysmon, network speed test, reliability improvements, and security fixes.
2026-05-22 05:46 UTC -
web:cybersecuritynews.com
Microsoft released its March 2026 Patch Tuesday security update on March 10, 2026, addressing 78 vulnerabilities across Windows, Microsoft Office, Azure, SQL Server, and .NET. The update includes one actively exploited zero-day vulnerability and multiple Critical-rated flaws demanding immediate attention from security teams. The most urgent fix this month is CVE -2026-21262, the sole zero-day ...
2026-05-22 05:46 UTC -
web:nvd.nist.gov
An official website of the United States government Here's how you know
2026-05-22 05:46 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 05:46 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's March 2026 Patch Tuesday with security updates for 79 flaws, including 2 publicly disclosed zero-day vulnerabilities.
2026-05-22 05:46 UTC -
web:www.crowdstrike.com
Microsoft's March 2026 Patch Tuesday addresses 82 CVEs , featuring eight Critical vulnerabilities.
2026-05-22 05:46 UTC -
web:www.neowin.net
Windows 11's March 2026 Patch Tuesday update is here under KB5079473 with File Explorer improvements and more.
2026-05-22 05:46 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2023-21762.json.
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T09:51:50.079Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "Microsoft Exchange Server Spoofing Vulnerability",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21762"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-21762",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-02-28T20:23:26.798051Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-02-28T21:14:23.383Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server 2016 Cumulative Update 23",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.01.2507.017",
"status": "affected",
"version": "15.01.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server 2019 Cumulative Update 12",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.02.1118.021",
"status": "affected",
"version": "15.02.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server 2019 Cumulative Update 11",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.02.0986.037",
"status": "affected",
"version": "15.02.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server 2013 Cumulative Update 23",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.00.1497.045",
"status": "affected",
"version": "15.00.0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:*:cumulative_update_23:*:*:*:*:*:*",
"versionEndExcluding": "15.01.2507.017",
"versionStartIncluding": "15.01.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:*:cumulative_update_12:*:*:*:*:*:*",
"versionEndExcluding": "15.02.1118.021",
"versionStartIncluding": "15.02.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:*:cumulative_update_11:*:*:*:*:*:*",
"versionEndExcluding": "15.02.0986.037",
"versionStartIncluding": "15.02.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:*:cumulative_update_23:*:*:*:*:*:*",
"versionEndExcluding": "15.00.1497.045",
"versionStartIncluding": "15.00.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2023-01-10T08:00:00.000Z",
"descriptions": [
{
"lang": "en-US",
"value": "Microsoft Exchange Server Spoofing Vulnerability"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-502",
"description": "CWE-502: Deserialization of Untrusted Data",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-01-01T00:36:06.138Z",
"orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"shortName": "microsoft"
},
"references": [
{
"name": "Microsoft Exchange Server Spoofing Vulnerability",
"tags": [
"vendor-advisory"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21762"
}
],
"title": "Microsoft Exchange Server Spoofing Vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"assignerShortName": "microsoft",
"cveId": "CVE-2023-21762",
"datePublished": "2023-01-10T00:00:00.000Z",
"dateReserved": "2022-12-13T00:00:00.000Z",
"dateUpdated": "2025-02-28T21:14:23.383Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}