Executive brief
Microsoft Exchange Server contains an elevation of privilege vulnerability due to improper authentication. The flaw allows a remote, unauthenticated attacker to escalate privileges on the system. This vulnerability has been confirmed to be exploited in the wild.
Affected products
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 13
- Microsoft Exchange Server 2019 Cumulative Update 14
Timeline
- 2024-02-13: disclosed: Initial disclosure by Microsoft Corporation
- 2024-02-15: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog
- 2024-03-07: other: CISA due date for required mitigation action