vulns.coMCP

← CVE intelligence

CVE-2023-21529 - Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.

Severity
critical
Product
Microsoft Exchange Server
Published
2026-04-13
EPSS
0.593
CISA KEV
Known exploited
Ransomware
Known campaign use

References and validation

Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.