← Vulnerability feed

Vulnerability record · CVE-2023-32031 · published 14 June 2023

CVE-2023-32031: Microsoft Exchange Server deserialization flaw enables remote code execution

Microsoft · Exchange Server

CVE-2023-32031 is a remote code execution vulnerability in Microsoft Exchange Server, classified by NVD under CWE-502 (deserialization of untrusted data) with an additional no-information CWE entry. The record gives only a one-line description, so the specific vulnerable component and code path are not stated. It matters because Exchange is internet-facing in many environments and successful exploitation yields code execution in the server context.

8.8 CVSS 3.1 High EPSS 81% · top 0.4% CWE-502 · Deserialization of untrusted data
8.8CVSS 3.1 base score
81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 8.8 with network reachability and high EPSS (99.62nd percentile) make this a serious risk, though the required low privileges and absence of KEV listing keep it below critical.

What it is

CVE-2023-32031 is a remote code execution vulnerability in Microsoft Exchange Server, classified by NVD under CWE-502 (deserialization of untrusted data) with an additional no-information CWE entry. The record gives only a one-line description, so the specific vulnerable component and code path are not stated. It matters because Exchange is internet-facing in many environments and successful exploitation yields code execution in the server context.

Impact

An authenticated attacker can execute arbitrary code on the Exchange server, gaining the privileges of the service process. That can lead to full compromise of the mail server and its hosted data.

Attack surface

The CVSS vector is network-reachable (AV:N) with low attack complexity and no user interaction, but it requires low privileges (PR:L), so the attacker needs some valid authenticated access. The record does not specify which Exchange endpoint or protocol is involved.

Exploitation

CISA KEV does not list this CVE, and no ransomware use is documented. EPSS is very high (0.8145, 99.62nd percentile), indicating strong predicted likelihood of exploitation, but the record contains no confirmed in-the-wild evidence.

What to do

  • Apply the Microsoft Exchange Server security update referenced in the MSRC advisory for CVE-2023-32031 as the first action.
  • Verify Exchange cumulative and security update levels across all servers, including edge and hybrid roles, and remediate any that are behind.
  • Restrict network exposure of Exchange endpoints (OWA, ECP, EWS, Autodiscover) to trusted networks or a VPN where operationally feasible.
  • Enforce least privilege and strong authentication for Exchange accounts, and review accounts with elevated or mailbox-impersonation rights.
  • Monitor for post-exploitation activity on Exchange hosts, including unexpected child processes from Exchange binaries and new web shells.

Detection

  • Alert on unusual child processes spawned by Exchange worker processes (w3wp.exe, Microsoft.Exchange.*) on mailbox and edge servers.
  • Hunt for newly written .aspx or other executable files in Exchange web directories and other IIS-served paths.
  • Review Exchange logs for anomalous authenticated requests to OWA, ECP, EWS or Autodiscover from unusual source addresses or accounts.
  • Correlate Exchange server process creation and file-write telemetry with authentication events to spot exploitation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-32031 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-21410Microsoft Exchange Server improper authentication privilege escalationCVE-2024-21410 is an improper authentication (CWE-287) elevation of privilege flaw in Microsoft Exchange Server. It is network-reachable with no priv…KEVEPSS 13%analysed9.1CVE-2021-34473Microsoft Exchange Server SSRF Enables Remote Code ExecutionCVE-2021-34473 is a critical server-side request forgery (SSRF) flaw in Microsoft Exchange Server that leads to remote code execution. It is part of …KEVEPSS 100%analysed9.1CVE-2021-26855Microsoft Exchange Server SSRF enabling remote code executionCVE-2021-26855 is a server-side request forgery (CWE-918) in Microsoft Exchange Server that is part of the ProxyLogon exploit chain and can lead to r…KEVEPSS 100%analysed9.0CVE-2021-34523Microsoft Exchange Server privilege escalation flawCVE-2021-34523 is a privilege escalation vulnerability in Microsoft Exchange Server. It is a component of the ProxyShell exploit chain, where it is u…KEVEPSS 100%analysed8.8CVE-2023-21529Microsoft Exchange Server deserialization flaw enables remote code executionCVE-2023-21529 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft Exchange Server that allows remote code execution. It carr…KEVEPSS 59%analysed8.8CVE-2022-41080Microsoft Exchange Server elevation of privilegeCVE-2022-41080 is an elevation of privilege vulnerability in Microsoft Exchange Server. A network-reachable attacker with low privileges can exploit …KEVEPSS 77%analysed8.8CVE-2022-41040Microsoft Exchange Server SSRF elevation of privilegeCVE-2022-41040 is a server-side request forgery (SSRF) flaw in Microsoft Exchange Server that allows an authenticated attacker to escalate privileges…KEVEPSS 100%analysed8.8CVE-2021-42321Microsoft Exchange Server remote code execution flawCVE-2021-42321 is a remote code execution vulnerability in Microsoft Exchange Server. It is remotely reachable over the network with low complexity, …KEVEPSS 92%analysed

Source: NIST National Vulnerability Database (record CVE-2023-32031), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.