Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
In November 2023, Microsoft said one of four Exchange vulnerabilities disclosed by Trend Micro’s Zero Day Initiative (ZDI) had already been addressed by its August 2023 security updates; the other three did not meet Microsoft’s bar for immediate servicing. ZDI called all four “zero-day” vulnerabilities, but the contemporaneous reporting did not indicate exploitation in the wild. This is a historical account, not confirmation of the patch status of any Exchange server today.
What happened in November 2023
On November 2, 2023, ZDI published four Exchange vulnerability advisories crediting researcher Piotr Bazydlo. ZDI said the findings had been reported to Microsoft in early September and that Microsoft had determined they did not require immediate servicing. On November 6, SecurityWeek reported Microsoft’s response: one issue had already been addressed, while the remaining reports did not meet the company’s immediate-servicing threshold.
Microsoft’s spokesperson, whom SecurityWeek did not name, said: “We appreciate the work of this finder submitting these issues under coordinated vulnerability disclosure, and we’re committed to taking the necessary steps to help protect customers. We’ve reviewed these reports and have found that they have either already been addressed, or do not meet the bar for immediate servicing under our severity classification guidelines and we will evaluate addressing them in future product versions and updates as appropriate,” SecurityWeek reported.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →How the four Exchange reports differed
All four ZDI advisories listed Exchange as the affected product and required authentication. The technical impacts were not the same: one report described potential code execution, while three described server-side request forgery (SSRF) leading to information disclosure. The CVSS scores below are ZDI’s advisory scores, not evidence that exploitation occurred.
#1 Best Overall
| ZDI advisory | Reported vulnerable method and impact | Authentication | ZDI CVSS | Microsoft’s reported position |
|---|---|---|---|---|
| ZDI-23-1578 | Untrusted-data deserialization in ChainedSerializationBinder; ZDI said authenticated remote exploitation could execute code as SYSTEM. |
Required | 7.5 | Microsoft said it had been patched and that customers who applied the August 2023 security updates were protected. |
| ZDI-23-1579 | Improper URI validation in DownloadDataFromUri, described as SSRF leading to information disclosure in the Exchange server context. |
Required | 7.1 | Did not meet Microsoft’s threshold for immediate servicing. |
| ZDI-23-1580 | Improper URI validation in DownloadDataFromOfficeMarketPlace, described as SSRF leading to information disclosure in the Exchange server context. |
Required | 7.1 | Did not meet Microsoft’s threshold for immediate servicing. |
| ZDI-23-1581 | Improper URI validation in CreateAttachmentFromUri, described as SSRF leading to information disclosure in the Exchange server context. |
Required | 7.1 | Did not meet Microsoft’s threshold for immediate servicing. |
ZDI’s advisories for the three SSRF findings describe a failure to validate a URI before accessing resources. Microsoft told SecurityWeek that, for two SSRF reports, no evidence had been presented of privilege escalation or access to sensitive customer information. The report does not identify which two advisories Microsoft meant, so that statement cannot be assigned to specific rows above. SecurityWeek’s account of Microsoft’s response distinguishes that assessment from ZDI’s technical descriptions.
What “zero-day” meant in this disclosure
“Zero-day” was the label ZDI used for its advisories; it should not be read as proof that attackers were exploiting the flaws. At disclosure, SecurityWeek said it had no indication of exploitation in the wild and no public technical details or proof-of-concept code that would increase near-term exploitation chances. The report also noted that exploitation required authentication and assessed the vulnerabilities as less likely to be leveraged in attacks. That was a risk assessment at the time, not a guarantee of safety.
Rank #2
- Server 2022 Standard 16 Core
A contemporaneous BleepingComputer search-result headline used the phrase “Microsoft Exchange zero-days allow RCE, data theft attacks.” A headline describing potential impact is not evidence that data theft attacks were observed. The available reporting supports discussing possible consequences, not claiming confirmed incidents.
What the 2023 statements mean for Exchange administrators
ZDI’s advisories gave the same mitigation language for each issue: “Given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the application.” For ZDI-23-1578, Microsoft’s reported guidance was that applying the August 2023 security updates protected customers. Neither statement establishes the present-day status of a server or the current remediation advice for a particular Exchange version.
Quick Recap
Best Value
- Used Book in Good Condition
Rank #4
Rank #3
- Check the Exchange version and build in your environment, then consult Microsoft’s current, version-specific security and support documentation.
- Verify whether the applicable updates are installed rather than inferring protection from the historical August 2023 statement.
- Use current Microsoft guidance to determine any remediation or access controls for the three SSRF reports; the 2023 coverage does not establish whether later updates changed their status.
- Consider ZDI’s historical suggestion to restrict interaction with the application as context, not as a substitute for current vendor instructions.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

