A robust email, calendaring, and collaboration platform developed by Microsoft, designed for enterprise-level communication and data management.Miscellaneous topics that do not fit into specific categories.
Hi @c5411
I'm another user here, not a Microsoft employee, so I can't give you the authoritative statement you're asking for. Below is what I could confirm from public sources and where the gap is.
The published CVE record describes CVE-2024-43590 as an elevation-of-privilege vulnerability in the Visual C++ Redistributable Installer. Its affected-product data lists the Visual C++ Redistributable Installer from version 10.0.0 up to, but not including, 14.40.33816.
However, I could not find an authoritative Microsoft statement that specifically confirms any of the following:
- whether the installed VC++ 2013 runtime files at version 12.0.40664 are exploitable in an Exchange Server SE configuration;
- whether the CVE applies only to vulnerable installer behaviour or also to the installed VC12 runtime DLLs;
- a supported Exchange-specific replacement or remediation for VC++ 2013;
- or approval to suppress this finding in vulnerability-management products.
Microsoft’s Visual C++ download guidance treats Visual Studio 2013 and the current v14 runtime as separate redistributable families. It also advises customers attempting to update a runtime required by an application to obtain instructions from the application vendor. Therefore, installing v14 alongside VC++ 2013 should not by itself be treated as remediation for the VC12 dependency.
Ref: Microsoft Visual C++ Redistributable latest supported downloads
For that reason, I would not recommend uninstalling or manually replacing the VC++ 2013 runtime on an Exchange server solely to clear the scanner finding. I also would not suppress the CVE based only on the fact that VC++ 2013 is an Exchange prerequisite, because the sources currently available do not provide an Exchange-specific non-applicability statement.
In this situation, I recommend opening a support request through your organisation’s Microsoft support agreement or contacting MSRC directly. In the request, please clearly include the CVE number, Visual C++ 2013 version 12.0.40664, and the Exchange Server SE prerequisites documentation.
You may also consider opening a support case through the Engage Center, where a specialised support engineer can review the configuration and provide an authoritative applicability statement. Please note that this type of support request may be chargeable depending on your organisation’s support agreement, so I recommend reviewing the applicable support terms before submitting the case.