logo

UK Electoral Commission had an unpatched Microsoft Exchange Server vulnerability

ID: 09b71555-1522-579d-b513-30b6c2e2632f

STIX ID: report--09b71555-1522-579d-b513-30b6c2e2632f

Feed Name: DoublePulsar

Threat Score
88/100

Date Published: 2023-08-09

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

The report examines how Microsoft Exchange Server 2016 (version 15.1.2507.12) was vulnerable to the ProxyNotShell zero-day in late September 2022; Microsoft initially provided mitigations that were repeatedly bypassed until a full security update in November 2022, and the flaw allowed remote code execution and potential full network compromise of affected Exchange deployments, with real-world impact illustrated by the Rackspace Hosted Exchange breach.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.