Junglewise Threat Intelligence

CVE-2023-21529: Microsoft Exchange Server deserialization remote code execution

CVE-2023-21529 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2026-04-13

Technologies: Microsoft Exchange Server 2016, Microsoft Exchange Server, Microsoft Exchange Server 2019. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server is a widely used platform for corporate email, calendaring, and collaboration. A security flaw allows an attacker with basic user credentials to take full control of the email server. This could lead to the theft of sensitive communications, disruption of business operations, or serve as a foothold for ransomware attacks within the organization.

Technical details

A deserialization vulnerability (CWE-502) exists in Microsoft Exchange Server due to the improper handling of untrusted data. An attacker with low-privileged credentials can exploit this flaw over the network without user interaction. Successful exploitation allows the attacker to execute arbitrary code in the context of the server, potentially leading to full system compromise. This vulnerability has been observed being exploited in the wild, specifically in association with ransomware operations. Microsoft has released patches to address this issue across supported versions of Exchange Server.

Affected products

  • Microsoft Exchange Server 2013 Cumulative Update 23
  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server 2019 Cumulative Update 11, Cumulative Update 12

Timeline

  • 2023-02-14: disclosed: Initial NVD publication date
  • 2024-11-21: patched: Microsoft update guide reference added
  • 2026-04-13: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats