Lucene search

K
mscveMicrosoftMS:CVE-2023-21706
HistoryFeb 14, 2023 - 8:00 a.m.

Microsoft Exchange Server Remote Code Execution Vulnerability

2023-02-1408:00:00
Microsoft
msrc.microsoft.com
22
microsoft
exchange server
remote code execution
vulnerability

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.013

Percentile

86.1%

Affected configurations

Vulners
Node
microsoftexchange_serverRange<15.00.1497.047
OR
microsoftexchange_serverRange<15.02.0986.041
OR
microsoftexchange_serverRange<15.01.2507.021
OR
microsoftexchange_serverRange<15.02.1118.025
VendorProductVersionCPE
microsoftexchange_server*cpe:2.3:a:microsoft:exchange_server:*:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.013

Percentile

86.1%