SB2023011045 - Multiple vulnerabilities in Microsoft Exchange Server
Published: January 10, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 secuirty vulnerabilities.
1) Man-in-the-Middle (MitM) attack (CVE-ID: CVE-2023-21745)
The vulnerability allows a remote user to perform spoofing attack.
The vulnerability exists due to unspecified error. A remote user on the local network can perform spoofing attack.
2) Information disclosure (CVE-ID: CVE-2023-21761)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can gain unauthorized access to sensitive information on the system.
3) Man-in-the-Middle (MitM) attack (CVE-ID: CVE-2023-21762)
The vulnerability allows a remote user to perform MitM attack.
The vulnerability exists due to unspecified error. A remote user on the local network can perform spoofing attack and obtain NTLM hashes of other Exchange users.
4) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2023-21763)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improperly imposed security restrictions. A local user can execute arbitrary code with SYSTEM privileges.5) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2023-21764)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improperly imposed security restrictions. A local user can execute arbitrary code with SYSTEM privileges.
Remediation
Install update from vendor's website.
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2023-21745
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2023-21761
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2023-21762
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2023-21763
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2023-21764