Skip to content
COOEY

EXPOSURES › CVE-2023-21529

CVE-2023-21529

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-04-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-21529 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 ransomwarerceexploited-in-wildunpatched

Microsoft Exchange Server allows authenticated attackers to execute remote code via deserialization of untrusted data.

This vulnerability enables remote code execution in Microsoft Exchange Server, allowing attackers to compromise mail servers and potentially access sensitive data. DIB organizations must patch immediately to prevent ransomware exploitation and maintain FedRAMP/NIST 800-171 compliance. Failure to patch exposes organizations to data breaches and potential FCA penalties.

Shame score — A critical RCE vulnerability in a widely deployed product that was actively exploited and linked to ransomware.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized