Vulnerability record · CVE-2023-36039 · published 14 November 2023
CVE-2023-36039: Microsoft Exchange Server spoofing flaw with deserialization risk
Microsoft · Exchange Server
CVE-2023-36039 is a spoofing vulnerability in Microsoft Exchange Server, with the NVD also mapping it to CWE-502 (deserialization of untrusted data). The record is thin: the description is a single line and no affected versions or component details are given, so the exact mechanism cannot be confirmed from this data alone.
Description
Microsoft Exchange Server Spoofing Vulnerability
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.0 with high confidentiality, integrity and availability impact and a very high EPSS score, though exploitation is not confirmed in KEV and the record lacks detail.
What it is
CVE-2023-36039 is a spoofing vulnerability in Microsoft Exchange Server, with the NVD also mapping it to CWE-502 (deserialization of untrusted data). The record is thin: the description is a single line and no affected versions or component details are given, so the exact mechanism cannot be confirmed from this data alone.
Impact
An attacker with low privileges on an adjacent network segment could achieve high confidentiality, integrity and availability impact, per the CVSS vector. In practice this means potential spoofing of Exchange content or identity and, if the deserialization mapping holds, possible code execution in the Exchange context.
Attack surface
The CVSS vector is AV:A/AC:L/PR:L/UI:N, so the flaw is reached from an adjacent network with low privileges required and no user interaction. It is not remotely exploitable over the internet by an unauthenticated attacker based on this vector.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented. EPSS is very high at 0.72992 (99.4th percentile), indicating strong predicted exploitation activity, but the references only carry Patch and Vendor Advisory tags, so no public exploit is confirmed here.
What to do
- Apply the Microsoft Exchange Server security update from the MSRC advisory for CVE-2023-36039.
- Restrict network access to Exchange services so only trusted internal hosts can reach them, reducing the adjacent-network exposure the vector requires.
- Enforce least privilege on Exchange accounts and review accounts with elevated or mailbox-impersonation rights.
- Monitor MSRC and NVD for updated affected-version and component details, since this record does not list them.
Detection
- Alert on anomalous Exchange authentication or mailbox access from hosts outside expected internal subnets.
- Monitor Exchange server processes for unexpected child processes or deserialization-related activity.
- Track Exchange patch levels against the MSRC advisory and flag unpatched servers.
- Review Exchange logs for spoofing indicators such as forged sender or identity changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36039 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36039 | PatchVendor Advisory |
Track CVE-2023-36039 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-36039), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.