CVE-2023-36745 is a critical Remote Code Execution vulnerability affecting Microsoft Exchange Server. With a CVSS score of 8.0 (HIGH), it allows an authenticated attacker on an adjacent network to execute arbitrary code with high impact on confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog and lacking public exploit code, its high EPSS score and significant community discussion indicate a strong potential for future exploitation. Media reports highlight over 20,000 vulnerable Exchange servers, underscoring the urgency for patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_23:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_12:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_13:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.