QID 50137
Date Published: 2024-03-13
QID 50137: Microsoft Exchange Server Multiple Vulnerabilities for March 2024
Microsoft Exchange Server 2019 and 2016 are affected by multiple vulnerabilities.
KB Articles associated with this update are: KB5036402, KB5036401, KB5036386
Affected Versions:
Microsoft Exchange Server 2019 Cumulative Update 14
Microsoft Exchange Server 2019 Cumulative Update 13
Microsoft Exchange Server 2016 Cumulative Update 23
QID Detection Logic (Authenticated):
The QID checks for vulnerable version of Microsoft Exchange Server 2019 by checking the file version of Exsetup.exe.
For Microsoft Exchange Server 2016, please see the vendor advisory for CVE-2024-26198.
QID Detection Logic: (Unauthenticated)
This QID sends a HTTP GET request to "/owa" endpoint and checks for vulnerable version of Microsoft Exchange Server.
Successful exploitation of the vulnerability may allow remote code execution and spoofing.
- CVE-2024-26198 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26198
CVEs related to QID 50137
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| KB5036386 |
|
||
| KB5036401 |
|
||
| KB5036402 |
|