Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Are earlier Cumulative Updates still vulnerable? #5

Open
kschluns opened this issue Mar 16, 2024 · 2 comments
Open

Are earlier Cumulative Updates still vulnerable? #5

kschluns opened this issue Mar 16, 2024 · 2 comments

Comments

@kschluns
Copy link
Contributor

kschluns commented Mar 16, 2024

In the example below for CVE-2023-36439, Microsoft only lists 3 affected products:
image

NVD also displays only 3 affected products:
image

I would think within a given Exchange Server version that all earlier cumulative updates would also be vulnerable. For example, with Exchange Server 2019, would RTM through CU11 also be vulnerable?

Right now the repo is not accounting for these prior builds being vulnerable and I was going to propose a solution for this, but before I do, I wanted to check with someone about whether this is actually the right logic.

@righel
Copy link
Owner

righel commented Mar 18, 2024

I'm not sure it is safe to assume that all prior cumulative updates are vulnerable too.
In your example for CVE-2023-36439, for Exchange Server 2019, two CU are listed 12 and 13, but not 11 or previous.
I hope they are reporting properly this and checking whether older CU are vulnerable too, but I cannot confirm this logic is true in all the cases.

@righel
Copy link
Owner

righel commented Mar 18, 2024

In any case I'll leave this one open in case someone can bring more information on this topic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants