Microsoft Exchange Server Remote Code Execution Vulnerability
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NMicrosoft Exchange Server
APPMicrosoft201320162019
CISA KEV — detailsi
- Vendori
- Microsoft ↗
- Producti
- Exchange Server
- Added to KEVi
- November 3, 2021
- Remediation deadline (US Federal)i
- November 17, 2021(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Required action (CISA)i
Apply updates per vendor instructions.
CISA descriptioni
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
☠️WYKORZYSTYWANE W RANSOMWARE⏰CISA DEADLINE: 17 listopada 2021
Tags
RCE
Related vulnerabilities
CVE-2024-21410CRITICAL9.8⚠ KEVPL ✓same product
Microsoft Exchange Server — privilege escalation z pominięciem uwierzytelnienia
CVE-2021-34523CRITICAL9.0⚠ KEVPL ✓same product
Microsoft Exchange Server — Elevation of Privilege (ProxyShell)
CVE-2021-26855CRITICAL9.1⚠ KEVPL ✓same product
Microsoft Exchange Server — krytyczny SSRF umożliwiający RCE (ProxyLogon)
CVE-2026-55008CRITICAL9.6PL ✓same product
XSS w Microsoft Exchange Server umożliwiający spoofing sieciowy
CVE-2023-21709CRITICAL9.8PL ✓same product
Microsoft Exchange Server — podatność na privilege escalation przez brak ograniczeń logowania