CVE

Exchange deserialization RCE (CVE-2023-21529)

Flag Microsoft Exchange hosts for CVE-2023-21529 by reading the OWA version path on GET /owa/auth/logon.aspx. 15.0/15.1/15.2 floors. No deser RCE.

AuthorTrickest
100%

Notes on this workflow

CVE-2023-21529 — Microsoft Exchange RCE

What this checks: whether a Microsoft Exchange host runs a version affected by authenticated deserialization RCE (CWE-502). Read-only: it fingerprints Microsoft Exchange and reads the version, no exploitation.

3. Detection — reads the Microsoft Exchange version from the version exposed at /owa/auth/logon.aspx, compares to Feb 2023 SU (KB5023038): 2013 CU23 15.0.1497.47 | 2016 CU23 15.1.2507.21 | 2019 CU11 15.2.986.41 | 2019 CU12 15.2.1118.25. Flags vulnerable on an affected build. No exploitation.

1. Target List — paste your Microsoft Exchange URLs here, one per line (e.g. https://host.example.com).

Overview

This workflow finds Microsoft Exchange Server and sorts each host by whether its OWA build falls below the CVE-2023-21529 fixed floors. CVE-2023-21529 is a deserialization flaw in Exchange that can lead to remote code execution on vulnerable builds. This check never deserializes input and never sends an authenticated RCE probe. Give it hostnames, IP addresses, or URLs you are authorised to test. The workflow GETs /owa/auth/logon.aspx, fingerprints Exchange from OWA markers on that page, parses the version from the /owa/auth/<build>/ path, and compares that tuple to the 15.0, 15.1, and 15.2 bands in the graph. Every host comes back affected or not, so a fleet advisory becomes an evidenced list for exposure management. There is no POST or SOAP confirm and no deserialization payload.

Run it on a schedule when Exchange cumulative updates lag. A CAS host still on a pre-February 2023 SU build is the reason the same fingerprint stays useful.

Pipeline

  1. Read the target list. Hosts, URLs, or ranges, one per line, become the scope.
  2. GET /owa/auth/logon.aspx on each host and fingerprint Exchange from markers such as /owa/auth/, logon.aspx, X-OWA-Version, and Microsoft Exchange strings.
  3. Parse the build from the /owa/auth/<n.n.n.n>/ path and compare it to the CVE-2023-21529 15.0 / 15.1 / 15.2 floors in the graph.
  4. Collect the per-host rows: product match, version, vulnerable flag, and any fetch error.
  5. Emit the summary counts: hosts checked, product hits, vulnerable, and errors.

Inputs

  • Target scope. Hostnames, IP addresses, CIDR ranges, or URLs, one per line. Full URLs and host:port entries work too, since the workflow normalizes each into a bare host. Point it at scope you are authorised to test.

Outputs

  • results.jsonl. One row per host: URL, whether Exchange was detected, the version read, the vulnerable flag, and detail text.
  • findings.jsonl. The same per-host verdict shaped for triage, with severity set from the vulnerable flag.
  • summary.json. Counts across the list: targets, product hits, vulnerable, and errors, plus the detection notes from the graph.

Integrations

  • HTTP. Unauthenticated GET of /owa/auth/logon.aspx only. No deserialization probe, no authenticated RCE, and no SOAP or POST confirm.

Sample output

The records below are illustrative and do not come from a real run. They show one Exchange host below a CVE-2023-21529 floor, one at or above its band floor, and one host that is not the product.

urlis_productproduct_versionvulnerabledetail
https://mail.example.comtrue15.2.1118.20truebelow band floor 15.2.1118.25
https://mail.example.orgtrue15.2.1118.25falseat or above fixed release
https://shop.example.netfalsenullfalsenot identified as Microsoft Exchange Server
{"cve": "CVE-2023-21529", "total_targets": 3, "product_detected": 2, "vulnerable": 1, "errors": 0}

FAQ

Which Exchange versions does this flag?

Builds below the 15.0 / 15.1 / 15.2 floors in the graph: 15.0.1497.47, 15.1.2507.21, 15.2.986.41, and 15.2.1118.25. A version picks the matching band, then compares to that band's floor. When no band matches, the graph falls back to FIXED 15.2.1118.25. The compare uses the OWA path version on /owa/auth/logon.aspx.

Does an affected row mean deserialization RCE worked?

No. The check only GETs /owa/auth/logon.aspx and reads the OWA version path. It does not deserialize input, does not authenticate, and does not confirm RCE.

Is this check safe on production?

Yes. It is a read-only unauthenticated GET of the public OWA logon page. It does not log in or send a deserialization payload.

Does the check need credentials?

No. It fingerprints the public OWA logon page the way an external scanner would.

What is CVE-2023-21529?

A deserialization vulnerability in Microsoft Exchange Server that can lead to remote code execution on vulnerable builds. This workflow maps hosts to that CVE by OWA version exposure only.

Get a personalized demo

See Trickest in Action

A 30-minute walkthrough. We map the platform to your stack and answer pricing and deployment questions for your environment.