MS.Exchange.Meeting.Poll.Insecure.Deserialization
Description
This indicates an attack attempt to exploit an Insecure Deserialization vulnerability in Microsoft Exchange Server.
The vulnerability is due to insufficient sanitization when handling a malicious request. A remote attacker may be able to exploit this to disclose data or execute arbitrary code within the context of the application, via a crafted HTTP request.
Affected Products
Microsoft Exchange Server 2019 Cumulative Update 9
Microsoft Exchange Server 2016 Cumulative Update 20
Microsoft Exchange Server 2013 Cumulative Update 23
Microsoft Exchange Server 2016 Cumulative Update 19
Microsoft Exchange Server 2019 Cumulative Update 8
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2019-2016-and-2013-april-13-2021-kb5001779-8e08f3b3-fc7b-466c-bbb7-5d5aa16ef064
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2022-07-13 | 21.355 | Sig Added |
2021-11-16 | 18.197 | Sig Added |
2021-11-04 | 18.191 | Sig Added |
2021-05-27 | 18.086 | Sig Added |
2021-05-19 | 18.082 | Sig Added |
2021-05-06 | 18.074 | Sig Added |
2021-05-05 | 18.073 | Default_action:pass:drop |
2021-04-28 | 18.069 | Name:MS. Exchage. Meeting. Poll. Insecure. Deserialization:MS. Exchange. Meeting. Poll. Insecure. Deserialization |
2021-04-27 | 18.068 |