Exchange Server SE requires VC++ 2013 12.0.40664, but CVE-2024-43590 reports affected Visual C++ Redistributable versions below 14.40.33816. What is Microsoft's supported remediation?

c5411 0 Reputation points
2026-10-06T00:11:58.1666667+00:00

I have an Exchange Server Subscription Edition Mailbox server with Microsoft Visual C++ 2013 Redistributable x64 12.0.40664 installed.

The actual VC12 runtime files are:

msvcr120.dll 12.0.40664.0 msvcp120.dll 12.0.40664.0 mfc120.dll 12.0.40664.0 mfc120u.dll 12.0.40664.0

Microsoft currently documents Visual C++ 2013 Redistributable as a prerequisite for the Exchange Server SE Mailbox role, and Exchange Setup requires that prerequisite.

At the same time, CVE-2024-43590 is published by MSRC as a Visual C++ Redistributable Installer Elevation of Privilege vulnerability. NVD identifies Microsoft Visual C++ Redistributable versions >=10.0.0 and <14.40.33816 in its affected configuration.

Installing the current VC++ v14 Redistributable does not replace VC++ 2013. Both are installed side-by-side on this server.

I am looking for an authoritative Microsoft answer to these questions:

  1. Is VC++ 2013 12.0.40664, as required by Exchange Server SE, considered affected by CVE-2024-43590 when installed as an Exchange prerequisite?
  2. If yes, what is Microsoft's supported remediation for Exchange Server SE?
  3. If no, where is Microsoft's authoritative applicability statement explaining why Exchange servers with VC++ 2013 12.0.40664 are not vulnerable?
  4. Should vulnerability-management products suppress CVE-2024-43590 when 12.0.40664 exists solely as an Exchange prerequisite, and if so, what Microsoft documentation supports that determination?

Removing VC++ 2013 is not a satisfactory remediation because Microsoft currently lists it as an Exchange Server SE Mailbox prerequisite. Installing VC++ v14 does not replace the VC12 runtime dependency.

Microsoft needs to clarify the supported security state of this configuration.

Exchange | Exchange Server | Other
Exchange | Exchange Server | Other

A robust email, calendaring, and collaboration platform developed by Microsoft, designed for enterprise-level communication and data management.Miscellaneous topics that do not fit into specific categories.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Michelle Nguyen 1,835 Reputation points Independent Advisor
    2026-10-06T01:30:10.8833333+00:00

    Hi @c5411

    I'm another user here, not a Microsoft employee, so I can't give you the authoritative statement you're asking for. Below is what I could confirm from public sources and where the gap is.

    The published CVE record describes CVE-2024-43590 as an elevation-of-privilege vulnerability in the Visual C++ Redistributable Installer. Its affected-product data lists the Visual C++ Redistributable Installer from version 10.0.0 up to, but not including, 14.40.33816.

    However, I could not find an authoritative Microsoft statement that specifically confirms any of the following:

    • whether the installed VC++ 2013 runtime files at version 12.0.40664 are exploitable in an Exchange Server SE configuration;
    • whether the CVE applies only to vulnerable installer behaviour or also to the installed VC12 runtime DLLs;
    • a supported Exchange-specific replacement or remediation for VC++ 2013;
    • or approval to suppress this finding in vulnerability-management products.

    Microsoft’s Visual C++ download guidance treats Visual Studio 2013 and the current v14 runtime as separate redistributable families. It also advises customers attempting to update a runtime required by an application to obtain instructions from the application vendor. Therefore, installing v14 alongside VC++ 2013 should not by itself be treated as remediation for the VC12 dependency.

    Ref: Microsoft Visual C++ Redistributable latest supported downloads

    For that reason, I would not recommend uninstalling or manually replacing the VC++ 2013 runtime on an Exchange server solely to clear the scanner finding. I also would not suppress the CVE based only on the fact that VC++ 2013 is an Exchange prerequisite, because the sources currently available do not provide an Exchange-specific non-applicability statement.

    In this situation, I recommend opening a support request through your organisation’s Microsoft support agreement or contacting MSRC directly. In the request, please clearly include the CVE number, Visual C++ 2013 version 12.0.40664, and the Exchange Server SE prerequisites documentation.

    You may also consider opening a support case through the Engage Center, where a specialised support engineer can review the configuration and provide an authoritative applicability statement. Please note that this type of support request may be chargeable depending on your organisation’s support agreement, so I recommend reviewing the applicable support terms before submitting the case.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.