#VU83069 Deserialization of Untrusted Data in Microsoft Exchange Server - CVE-2023-36050
Published: November 14, 2023 / Updated: December 8, 2023
Microsoft Exchange Server
Microsoft
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to insecure input validation when processing serialized data within the SerializationTypeConverter class in TransportConfigContainer. A remote user can pass specially crafted data to the application and gain access to sensitive information.