Summary
Microsoft Exchange Server has an authenticated remote code execution flaw in the PowerShell remoting deserialization path. A low-privileged Exchange user can send crafted serialized input that abuses the allowed MultiValuedProperty class and related type-conversion logic, causing the server to run attacker-controlled code. Successful exploitation can execute code as SYSTEM and fully compromise the mail server.
Why Planned Fix?
5/6Exploitation Details
Execute arbitrary code as SYSTEM on the Exchange server
Full System CompromiseAffected Software
| Product | Affected Versions |
|---|---|
| Microsoft Exchange Server 2013 | Cumulative Update 23 before SU20 |
| Microsoft Exchange Server 2016 | Cumulative Update 23 before SU6 |
| Microsoft Exchange Server 2019 | Cumulative Update 11 before SU10, Cumulative Update 12 before SU6 |
Microsoft Exchange Server is an on-premises email, calendaring, and collaboration platform used to host mailboxes and messaging services.
Affected ComponentExchange PowerShell remoting deserialization path, centered on the MultiValuedProperty class used by /powershell requests.
Exchange PowerShell remoting deserialization path, centered on the MultiValuedProperty class used by /powershell requests.
Affected Endpoints(1)/powershell
Not available
Not available
Install KB5023038: Exchange Server 2019 CU12 SU6 or CU11 SU10, Exchange Server 2016 CU23 SU6, or Exchange Server 2013 CU23 SU20.
Install KB5023038: Exchange Server 2019 CU12 SU6 or CU11 SU10, Exchange Server 2016 CU23 SU6, or Exchange Server 2013 CU23 SU20.
Probability of exploitation in the next 30 days
Worse than 97% of all CVEs
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Affected Software (CPE) (4)
- •cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_23:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_11:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_12:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| nvd.nist.gov | CVE-2023-21529 Detail |
| support.microsoft.com | Exchange Server security update KB5023038 |
| www.zerodayinitiative.com | ZDI-23-162 |
| www.microsoft.com | Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations |
| www.thezdi.com | Exploiting Exchange PowerShell After ProxyNotShell: Part 1 - MultiValuedProperty |
| cyberfortress.jp | March 2023 attack service statistics and analysis |
| www.tenable.com | CVE-2023-21529 |
| www.rapid7.com | Microsoft CVE-2023-21529 |
| github.com | tr1pl3ight/CVE-2023-21529-POC |
Priority History
Initial analysis