Microsoft Exchange Server vulnerabilities
219 known vulnerabilities affecting microsoft/exchange_server.
Total CVEs
219
CISA KEV
20
actively exploited
Public exploits
46
Exploited in wild
29
Severity breakdown
CRITICAL25HIGH89MEDIUM99LOW6
Vulnerabilities
Page 2 of 11
CVE-2021-28482P1HIGHCVSS 8.8ExploitedPoCRansomwarev2013v2016+1 more2021-04-13
CVE-2021-28482 [HIGH] CVE-2021-28482: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2018-0986P1HIGHCVSS 8.8ExploitedPoCRansomwarev2013v20162018-04-04
CVE-2018-0986 [HIGH] CWE-787 CVE-2018-0986: A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not p
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection, Microsoft Security Essentials, Microsoft
nvd
CVE-2021-28481P1CRITICALCVSS 9.8ExploitedPoCv2013v2016+1 more2021-04-13
CVE-2021-28481 [CRITICAL] CVE-2021-28481: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2020-16875P1HIGHCVSS 7.2ExploitedPoCRansomwarev2016v20192020-09-11
CVE-2020-16875 [HIGH] CWE-74 CVE-2020-16875: <p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validat
A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.
An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the vulnerability requires an authenticated user in a certain Exchange role to be compromised.
The
nvd
CVE-2021-31206P1HIGHCVSS 8.0ExploitedPoCRansomwarev2013v2016+1 more2021-07-14
CVE-2021-31206 [HIGH] CVE-2021-31206: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2021-34470P2HIGHCVSS 8.0ExploitedPoCv2013v2016+1 more2021-07-14
CVE-2021-34470 [HIGH] CVE-2021-34470: Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
nvd
CVE-2023-36745P1HIGHCVSS 8.0Exploitedv2016v20192023-09-12
CVE-2023-36745 [HIGH] CWE-502 CVE-2023-36745: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2021-33768P2HIGHCVSS 8.0Exploitedv2016v20192021-07-14
CVE-2021-33768 [HIGH] CVE-2021-33768: Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
nvd
CVE-2009-0099P2MEDIUMCVSS 5.0Exploitedv2000v2003+1 more2009-02-10
CVE-2009-0099 [MEDIUM] CWE-20 CVE-2009-0099: The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 S
The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server 2003 SP2, as used in Exchange System Attendant, allows remote attackers to cause a denial of service (application outage) via a malformed MAPI command, aka "Literal Processing Vulnerability."
nvd
CVE-2021-28480P1CRITICALCVSS 9.8PoCv2013v2016+1 more2021-04-13
CVE-2021-28480 [CRITICAL] CVE-2021-28480: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2020-17132P2CRITICALCVSS 9.1PoCv2013v2016+1 more2020-12-10
CVE-2020-17132 [CRITICAL] CVE-2020-17132: Microsoft Exchange Remote Code Execution Vulnerability
Microsoft Exchange Remote Code Execution Vulnerability
nvd
CVE-2021-31195P2HIGHCVSS 8.8PoCv2013v2016+1 more2021-05-11
CVE-2021-31195 [HIGH] CWE-290 CVE-2021-31195: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2022-23277P2HIGHCVSS 8.8PoCv2013v2016+1 more2022-03-09
CVE-2022-23277 [HIGH] CVE-2022-23277: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2007-0213P2CRITICALCVSS 10.0PoCv2000v2003+1 more2007-05-08
CVE-2007-0213 [CRITICAL] CWE-20 CVE-2007-0213: Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME
Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.
nvd
CVE-2006-0027P2HIGHCVSS 7.5PoCv2000v20032006-05-10
CVE-2006-0027 [HIGH] CVE-2006-0027: Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code vi
Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.
nvd
CVE-2004-0574P2CRITICALCVSS 10.0PoCv2000v20032004-11-03
CVE-2004-0574 [CRITICAL] CWE-787 CVE-2004-0574: The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000
The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-
nvd
CVE-2005-0560P2HIGHCVSS 7.5PoCv2000v20032005-05-02
CVE-2005-0560 [HIGH] CWE-787 CVE-2005-0560: Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP servic
Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port.
nvd
CVE-2019-0724P2HIGHCVSS 8.1PoCv2010v2013+2 more2019-03-05
CVE-2019-0724 [HIGH] CVE-2019-0724: An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0686.
nvd
CVE-2023-21707P2HIGHCVSS 8.8v2013v2016+1 more2023-02-14
CVE-2023-21707 [HIGH] CWE-502 CVE-2023-21707: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2023-32031P2HIGHCVSS 8.8v2016v20192023-06-14
CVE-2023-32031 [HIGH] CWE-502 CVE-2023-32031: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd