CVE-2019-1373

Description

A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka Microsoft Exchange Remote Code Execution Vulnerability.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
9.619

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Exchange Remote Code Execution Vulnerability For Exchange Server 2019 CU2 (KB4523171)Windows
Microsoft Exchange Remote Code Execution Vulnerability For Exchange Server 2019 CU3 (KB4523171)Windows
Microsoft Exchange Remote Code Execution Vulnerability For Exchange Server 2016 CU13 (KB4523171)Windows
Microsoft Exchange Remote Code Execution Vulnerability For Exchange Server 2016 CU14 (KB4523171)Windows
Microsoft Exchange Remote Code Execution Vulnerability For Exchange Server 2013 CU23 (KB4523171)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-27887Security Update For Exchange Server 2019 CU2 (KB4523171)
PATCH-27888Security Update For Exchange Server 2019 CU3 (KB4523171)
PATCH-27889Security Update For Exchange Server 2016 CU13 (KB4523171)
PATCH-27890Security Update For Exchange Server 2016 CU14 (KB4523171)
PATCH-27891Security Update For Exchange Server 2013 CU23 (KB4523171)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234