Executive brief
Microsoft Exchange Server is vulnerable to remote code execution due to insecure deserialization of untrusted data. This vulnerability is part of the ProxyLogon exploit chain and allows an attacker to execute arbitrary code in the context of the Unified Messaging service.
Affected products
- Microsoft Exchange Server 2010 Service Pack 3
- Microsoft Exchange Server 2013 Cumulative Update 23
- Microsoft Exchange Server 2016 Cumulative Update 18
- Microsoft Exchange Server 2016 Cumulative Update 19
- Microsoft Exchange Server 2019 Cumulative Update 7
- Microsoft Exchange Server 2019 Cumulative Update 8
Timeline
- 2021-03-08: disclosed: Initial analysis by NIST
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog