Microsoft Exchange Server is a widely used enterprise email, calendaring, and collaboration platform developed by Microsoft, designed to help organizations manage email, contacts, calendars, and tasks efficiently while supporting secure communication and integration with other Microsoft services. Due to its critical role in business operations and the sensitive information it handles, Exchange Server is a frequent target for cyberattacks, with vulnerabilities potentially leading to data breaches, unauthorized access, and system compromise.

This page provides a comprehensive, regularly updated list of significant Microsoft Exchange Server security vulnerabilities, each linked to its official CVE report at Microsoft’s Security Response Center. The aim is to help IT professionals, administrators, and security teams quickly identify, assess, and address known threats to ensure their Exchange environments remain secure.

Exchange Server Vulnerabilities for 2024

FEATURED PRODUCT

Stop Zero-Day Attacks Others Miss

Protect Microsoft Servers from zero-day attacks and penetrations that bypass traditional security. Real-time monitoring technology that detects, alerts, and cannot be disabled by malicious software.

START 30-DAY FREE TRIAL →

Exchange Server Vulnerabilities for 2023

CVEDescriptionReleasedSeverityActively Exploited
CVE-023-36439A high-severity vulnerability in Microsoft Exchange Server that allows remote attackers to execute arbitrary code via improper deserialization, potentially compromising the affected system. Microsoft Exchange Server Remote Code Execution Vulnerability.2023-11-148.0
CVE-2023-36050A high-severity vulnerability in Microsoft Exchange Server that allows unauthenticated attackers to spoof email addresses by exploiting improper handling of email addresses during delivery, potentially enabling phishing attacks. Microsoft Exchange Server Spoofing Vulnerability.2023-11-148.0
CVE-2023-36039A high-severity vulnerability in Microsoft Exchange Server that allows an unauthenticated attacker to perform email spoofing by manipulating email header information, potentially tricking recipients into revealing sensitive information or downloading malware. Microsoft Exchange Server Spoofing Vulnerability.2023-11-148.0
CVE-2023-36035A high-severity vulnerability in Microsoft Exchange Server that allows unauthenticated attackers to spoof emails by exploiting improper validation of email addresses during external message delivery, potentially enabling phishing attacks. Microsoft Exchange Server Spoofing Vulnerability.2023-11-148.0
CVE-2023-36778A high-severity vulnerability in Microsoft Exchange Server that allows a remote authenticated attacker to execute arbitrary code on the affected system, potentially leading to full system compromise. Microsoft Exchange Server Remote Code Execution Vulnerability2023-10-108.0
CVE-2023-36777An information disclosure vulnerability in Microsoft Exchange Server that allows authenticated attackers with LAN access to read sensitive file content from the server, potentially leading to data leaks if not patched. Microsoft Exchange Server Information Disclosure Vulnerability.2023-09-125.7
CVE-2023-36757A high-severity vulnerability in Microsoft Exchange Server that allows authenticated attackers to cause a denial-of-service condition by exploiting improper deserialization of untrusted data in the ExFileLog class. Microsoft Exchange Server Spoofing Vulnerability.2023-09-128.0
CVE-2023-36756 a high-severity vulnerability in Microsoft Exchange Server that allows authenticated attackers to achieve remote code execution by exploiting improper deserialization of untrusted data, potentially enabling them to upload a web shell and fully compromise the server. Microsoft Exchange Server Remote Code Execution Vulnerability.2023-09-128.0
CVE-2023-36745A high-severity remote code execution vulnerability in Microsoft Exchange Server that allows an unauthenticated attacker with LAN access to execute arbitrary code on the server by exploiting improper deserialization of untrusted data, potentially leading to full system compromise if left unpatched. Microsoft Exchange Server Remote Code Execution Vulnerability.2023-09-128.0
CVE-2023-36744A high-severity remote code execution vulnerability in Microsoft Exchange Server that allows authenticated attackers with LAN access to write arbitrary files to the server, which can be exploited as part of an attack chain to execute malicious code and potentially fully compromise the system. Microsoft Exchange Server Remote Code Execution Vulnerability.2023-09-128.0
CVE-2023-38185A high-severity remote code execution vulnerability in Microsoft Exchange Server that allows authenticated attackers to execute arbitrary code on the server, potentially by sending specially crafted emails or attachments, and poses a significant risk of unauthorized access and system compromise if left unpatched. Microsoft Exchange Server Remote Code Execution Vulnerability.2023-08-088.8
CVE-2023-38182A remote code execution vulnerability in Microsoft Exchange Server that allows an authenticated attacker on the same intranet to execute arbitrary code via a PowerShell remoting session, potentially leading to full system compromise. Microsoft Exchange Server Remote Code Execution Vulnerability2023-08-088.0
CVE-2023-38181High-severity spoofing vulnerability in Microsoft Exchange Server that allows authenticated attackers to manipulate email headers and potentially retrieve Net-NTLMv2 hashes via PowerShell remoting, increasing the risk of phishing and credential compromise. Microsoft Exchange Server Spoofing Vulnerability.2023-08-088.8
CVE-2023-35388A high-severity remote code execution vulnerability in Microsoft Exchange Server 2016 and 2019 that allows authenticated attackers with LAN access to execute arbitrary code on the server via a PowerShell remoting session. Microsoft Exchange Server Remote Code Execution Vulnerability.2023-08-088.0
CVE-2023-35368High-severity remote code execution vulnerability in Microsoft Exchange Server 2016 and 2019 that allows attackers to execute arbitrary code on affected servers without user interaction by exploiting improper input validation, potentially leading to full system compromise. Microsoft Exchange Remote Code Execution Vulnerability.2023-08-088.8
CVE-2023-21709Critical elevation of privilege vulnerability affecting Microsoft Exchange Server. The vulnerability allows unauthenticated attackers to perform brute force attacks against valid user accounts, potentially leading to unauthorized logins and privilege escalation.2023-08-089.8
CVE-2023-32031High-severity remote code execution vulnerability in Microsoft Exchange Server 2016 and 2019 that allows authenticated attackers to execute arbitrary code on the server by exploiting improper deserialization of untrusted data, potentially leading to full system compromise. Microsoft Exchange Server Remote Code Execution Vulnerability.2023-06-148.8
CVE-2023-28310A high-severity remote code execution vulnerability in Microsoft Exchange Server that allows authenticated attackers with LAN access to execute arbitrary code via a PowerShell remoting session, potentially leading to unauthorized access or data theft. Microsoft Exchange Server Remote Code Execution Vulnerability.2023-06-148.0
CVE-2023-21710A remote code execution vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows authenticated attackers to execute arbitrary code on the server as SYSTEM by sending specially crafted requests, potentially leading to full system compromise if left unpatched. Microsoft Exchange Server Remote Code Execution Vulnerability.2023-02-147.2
CVE-2023-21706High-severity remote code execution vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows authenticated attackers to execute arbitrary code on the server by exploiting improper deserialization of untrusted data, potentially leading to full system compromise. Microsoft Exchange Server Remote Code Execution Vulnerability.2023-02-148.8
CVE-2023-21707A high-severity remote code execution vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows authenticated attackers to execute arbitrary code on the server by exploiting improper deserialization of untrusted data. Microsoft Exchange Server Remote Code Execution Vulnerability.2023-02-148.8
CVE-2023-21529High-severity remote code execution vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows authenticated attackers to execute arbitrary code on the server by exploiting improper deserialization of untrusted data, potentially leading to full system compromise . Microsoft Exchange Server Remote Code Execution Vulnerability.2023-02-148.8
CVE-2023-21762A critical out-of-bounds write vulnerability in the SSL-VPN daemon (sslvpnd) of Fortinet FortiOS and FortiProxy products that allows unauthenticated remote attackers to execute arbitrary code or commands, potentially leading to complete system compromise, and has been actively exploited in the wild, prompting urgent recommendations to patch or disable SSL VPN functionality until remediation is applied. Microsoft Exchange Server Spoofing Vulnerability.2023-01-108.0⚠️
CVE-2023-21763An elevation of privilege vulnerability in Microsoft Exchange Server that allows authenticated attackers to gain SYSTEM-level privileges, potentially enabling unauthorized actions within the system. Microsoft Exchange Server Elevation of Privilege Vulnerability.2023-01-107.8
CVE-2023-21764High-severity elevation of privilege vulnerability in Microsoft Exchange Server 2016 and 2019 that allows a local authenticated attacker to load a malicious DLL via an externally-supplied search path, potentially gaining SYSTEM-level privileges on the affected server. Microsoft Exchange Server Elevation of Privilege Vulnerability.2023-01-107.8
CVE-2023-21761High-severity information disclosure vulnerability in Microsoft Exchange Server 2016 and 2019 that allows remote, unauthenticated attackers to access sensitive information due to improper validation of requests, potentially exposing confidential data over the network. Microsoft Exchange Server Information Disclosure Vulnerability.2023-01-107.5
CVE-2023-21745A high-severity spoofing vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows attackers to impersonate users or services, potentially enabling phishing attacks or unauthorized access if left unpatched. Microsoft Exchange Server Spoofing Vulnerability.2023-01-108.0

FEATURED SECURITY

Stop AD Account Lockouts

Real-time security bans attackers independently of Active Directory, eliminating password attacks through intelligent GEO blocking and preventing vulnerability probing without account lockouts or password resets.

ACTIVATE FOR 30 DAYS →

Exchange Server Vulnerabilities for 2022

CVEDescriptionReleasedSeverityActively Exploited
CVE-2022-41123High-severity elevation of privilege vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows local authenticated attackers to gain elevated privileges on the system, potentially enabling unauthorized actions if left unpatched. Microsoft Exchange Server Elevation of Privilege Vulnerability
2022-11-097.8
CVE-2022-41080A high-severity privilege escalation vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows authenticated attackers to elevate privileges and execute arbitrary code with SYSTEM rights, and can be combined with other vulnerabilities to bypass mitigations and achieve remote code execution. Microsoft Exchange Server Elevation of Privilege Vulnerability2022-11-099.8⚠️
CVE-2022-41079Spoofing vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows authenticated attackers to impersonate users or services by manipulating email or server responses, potentially enabling phishing or unauthorized access. Microsoft Exchange Server Spoofing Vulnerability2022-11-098.0
CVE-2022-41078High-severity spoofing vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows authenticated attackers to relay NTLM credentials, potentially enabling further attacks such as NTLM relay or impersonation if left unpatched. Microsoft Exchange Server Spoofing Vulnerability.2022-11-098.0
CVE-2022-41082A remote code execution vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows authenticated attackers to execute arbitrary code via PowerShell when combined with other vulnerabilities, potentially leading to full system compromise if left unpatched. Microsoft Exchange Server Remote Code Execution Vulnerability2022-10-038.0⚠️
CVE-2022-41040Server-side request forgery (SSRF) vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows an authenticated attacker to remotely trigger subsequent vulnerabilities-such as remote code execution via CVE-2022-41082-potentially leading to full system compromise. Microsoft Exchange Server Elevation of Privilege Vulnerability.2022-10-038.8⚠️
CVE-2022-34692Medium-severity information disclosure vulnerability in Microsoft Exchange Server 2016 and 2019 that allows attackers to access sensitive data on affected systems, potentially compromising confidentiality if left unpatched. Microsoft Exchange Server Information Disclosure Vulnerability.2022-08-095.3
CVE-2022-30134Information disclosure vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows authenticated attackers to read targeted email messages without requiring elevated privileges. Microsoft Exchange Server Information Disclosure Vulnerability.2022-08-096.5
CVE-2022-24516A high-severity elevation of privilege vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows authenticated attackers to gain elevated privileges on the system by enticing a user to access a malicious server, potentially resulting in unauthorized access and control. Microsoft Exchange Server Elevation of Privilege Vulnerability.2022-08-098.0
CVE-2022-24477High-severity elevation of privilege vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that requires an authenticated user to be enticed into visiting a malicious server, potentially allowing an attacker to take over user mailboxes, send and read emails, and download attachments if successfully exploited. Microsoft Exchange Server Elevation of Privilege Vulnerability.2022-08-098.0
CVE-2022-21979A medium-severity information disclosure vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows authenticated attackers to access sensitive information stored on the server, potentially leading to privacy breaches and data exposure. Microsoft Exchange Server Information Disclosure Vulnerability.2022-08-095.7
CVE-2022-21980High-severity elevation of privilege vulnerability in Microsoft Exchange Server 2016 and 2019 that requires an authenticated user to visit a malicious server, potentially allowing an attacker to gain elevated privileges and take control of Exchange resources. Microsoft Exchange Server Elevation of Privilege Vulnerability.2022-08-098.0
CVE-2022-21978A high-severity elevation of privilege vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows attackers with elevated privileges on the Exchange server to gain Domain Administrator rights, potentially leading to full domain compromise. Microsoft Exchange Server Elevation of Privilege Vulnerability.2022-05-108.2
CVE-2022-24463Spoofing vulnerability in Microsoft Exchange Server 2016 and 2019 that allows authenticated attackers to make specially crafted network calls, potentially causing the server to disclose files by parsing HTTP requests to attacker-controlled servers. Microsoft Exchange Server Spoofing Vulnerability.2022-03-096.5
CVE-2022-23277A critical remote code execution vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows authenticated attackers with low privileges to execute arbitrary code on the server by exploiting insecure deserialization, potentially leading to full system compromise if left unpatched. Microsoft Exchange Server Remote Code Execution Vulnerability.2022-03-098.8⚠️
CVE-2022-21969Critical remote code execution vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows attackers with adjacent network access and low privileges to execute arbitrary code on the server. Microsoft Exchange Server Remote Code Execution Vulnerability.2022-01-119.0
CVE-2022-21855A remote code execution vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows authenticated attackers with adjacent network access to execute arbitrary code on the server. Microsoft Exchange Server Remote Code Execution Vulnerability.2022-01-119.0
CVE-2022-21846Critical remote code execution vulnerability in Microsoft Exchange Server 2013, 2016, and 2019 that allows attackers with adjacent network access and low privileges to execute arbitrary code on the server. Microsoft Exchange Server Remote Code Execution Vulnerability.2022-01-119.0

FEATURED DOWNLOAD

PowerShell Commands for AD Lockouts

10 PowerShell commands every admin needs
Unlock users & find lockout sources instantly

Download our FREE Cheat Sheet

Exchange Server Vulnerabilities for 2021