QID 50136

Date Published: 2024-02-14

QID 50136: Microsoft Exchange Server Vulnerability for Feb 2024

Microsoft Exchange Server 2019 and 2016 are affected by multiple vulnerabilities.

KB Articles associated with this update are: KB5035606

Affected Versions:
Microsoft Exchange Server 2019 Cumulative Update 14 Microsoft Exchange Server 2019 Cumulative Update 13 Microsoft Exchange Server 2016 Cumulative Update 23

QID Detection Logic (Authenticated):
The QID checks for vulnerable version of Microsoft Exchange Server by checking the file version of Exsetup.exe.

Successful exploitation of the vulnerability may allow remote code execution and spoofing

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.7 severity.
  • Solution
    Microsoft has released patch, customers are advised to refer to KB5035606 for information pertaining to this vulnerability.

    CVEs related to QID 50136

    Software Advisories
    Advisory ID Software Component Link
    KB5035606 URL Logo support.microsoft.com/help/5035606