9.8

CVE-2023-21709

Microsoft Exchange Server Elevation of Privilege Vulnerability

Microsoft Exchange Server Elevation of Privilege Vulnerability
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Exchange Server Version 2016 Update -
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_1
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_10
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_11
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_12
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_13
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_14
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_15
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_16
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_17
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_18
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_19
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_2
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_20
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_21
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_22
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_3
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_4
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_5
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_6
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_7
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_8
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_9
Microsoft ≫ Exchange Server Version 2019 Update -
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_1
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_10
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_11
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_2
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_3
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_4
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_5
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_6
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_7
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_8
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.98% 0.787
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Microsoft 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-307 Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21709
Patch
Vendor Advisory