Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

In November 2023, Microsoft said one of four Exchange vulnerabilities disclosed by Trend Micro’s Zero Day Initiative (ZDI) had already been addressed by its August 2023 security updates; the other three did not meet Microsoft’s bar for immediate servicing. ZDI called all four “zero-day” vulnerabilities, but the contemporaneous reporting did not indicate exploitation in the wild. This is a historical account, not confirmation of the patch status of any Exchange server today.

What happened in November 2023

On November 2, 2023, ZDI published four Exchange vulnerability advisories crediting researcher Piotr Bazydlo. ZDI said the findings had been reported to Microsoft in early September and that Microsoft had determined they did not require immediate servicing. On November 6, SecurityWeek reported Microsoft’s response: one issue had already been addressed, while the remaining reports did not meet the company’s immediate-servicing threshold.

Microsoft’s spokesperson, whom SecurityWeek did not name, said: “We appreciate the work of this finder submitting these issues under coordinated vulnerability disclosure, and we’re committed to taking the necessary steps to help protect customers. We’ve reviewed these reports and have found that they have either already been addressed, or do not meet the bar for immediate servicing under our severity classification guidelines and we will evaluate addressing them in future product versions and updates as appropriate,” SecurityWeek reported.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the four Exchange reports differed

All four ZDI advisories listed Exchange as the affected product and required authentication. The technical impacts were not the same: one report described potential code execution, while three described server-side request forgery (SSRF) leading to information disclosure. The CVSS scores below are ZDI’s advisory scores, not evidence that exploitation occurred.

ZDI advisory Reported vulnerable method and impact Authentication ZDI CVSS Microsoft’s reported position
ZDI-23-1578 Untrusted-data deserialization in ChainedSerializationBinder; ZDI said authenticated remote exploitation could execute code as SYSTEM. Required 7.5 Microsoft said it had been patched and that customers who applied the August 2023 security updates were protected.
ZDI-23-1579 Improper URI validation in DownloadDataFromUri, described as SSRF leading to information disclosure in the Exchange server context. Required 7.1 Did not meet Microsoft’s threshold for immediate servicing.
ZDI-23-1580 Improper URI validation in DownloadDataFromOfficeMarketPlace, described as SSRF leading to information disclosure in the Exchange server context. Required 7.1 Did not meet Microsoft’s threshold for immediate servicing.
ZDI-23-1581 Improper URI validation in CreateAttachmentFromUri, described as SSRF leading to information disclosure in the Exchange server context. Required 7.1 Did not meet Microsoft’s threshold for immediate servicing.

ZDI’s advisories for the three SSRF findings describe a failure to validate a URI before accessing resources. Microsoft told SecurityWeek that, for two SSRF reports, no evidence had been presented of privilege escalation or access to sensitive customer information. The report does not identify which two advisories Microsoft meant, so that statement cannot be assigned to specific rows above. SecurityWeek’s account of Microsoft’s response distinguishes that assessment from ZDI’s technical descriptions.

What “zero-day” meant in this disclosure

“Zero-day” was the label ZDI used for its advisories; it should not be read as proof that attackers were exploiting the flaws. At disclosure, SecurityWeek said it had no indication of exploitation in the wild and no public technical details or proof-of-concept code that would increase near-term exploitation chances. The report also noted that exploitation required authentication and assessed the vulnerabilities as less likely to be leveraged in attacks. That was a risk assessment at the time, not a guarantee of safety.

A contemporaneous BleepingComputer search-result headline used the phrase “Microsoft Exchange zero-days allow RCE, data theft attacks.” A headline describing potential impact is not evidence that data theft attacks were observed. The available reporting supports discussing possible consequences, not claiming confirmed incidents.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the 2023 statements mean for Exchange administrators

ZDI’s advisories gave the same mitigation language for each issue: “Given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the application.” For ZDI-23-1578, Microsoft’s reported guidance was that applying the August 2023 security updates protected customers. Neither statement establishes the present-day status of a server or the current remediation advice for a particular Exchange version.

  • Check the Exchange version and build in your environment, then consult Microsoft’s current, version-specific security and support documentation.
  • Verify whether the applicable updates are installed rather than inferring protection from the historical August 2023 statement.
  • Use current Microsoft guidance to determine any remediation or access controls for the three SSRF reports; the 2023 coverage does not establish whether later updates changed their status.
  • Consider ZDI’s historical suggestion to restrict interaction with the application as context, not as a substitute for current vendor instructions.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.