QID 50128

QID 50128: Microsoft Exchange Server Elevation of Privilege Vulnerability Configuration Check (CVE-2023-21709)

Microsoft Exchange Server 2016 and 2019 are affected by multiple vulnerabilities.

KB Articles associated with this update are: KB5029388

Affected Versions:
Microsoft Exchange Server 2016 Cumulative Update 23
Microsoft Exchange Server 2019 Cumulative Update 12
Microsoft Exchange Server 2019 Cumulative Update 13

QID Detection Logic (Authenticated):
The QID checks for vulnerable version of Microsoft Exchange Server by checking the file version of Exsetup.exe.

Note: For CVE-2023-21709: There is script available run the CVE-2023-21709.ps1 script

Successful exploitation of the vulnerability may allow elevation of privilege

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Microsoft has released patch, customers are advised to refer to 5029388 for information pertaining to this vulnerability.

    CVEs related to QID 50128

    Software Advisories
    Advisory ID Software Component Link
    KB5029388 URL Logo support.microsoft.com/help/5029388