CVE-2021-24085HighCVSS 6.5

Microsoft Exchange Server Spoofing Vulnerability

Published
February 9, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What is the nature of the spoofing? An authenticated attacker can leak a cert file which results in a CSRF token to be generated.

🎯 Affected products4

  • Microsoft Exchange Server 2016 Cumulative Update 18
  • Microsoft Exchange Server 2016 Cumulative Update 19
  • Microsoft Exchange Server 2019 Cumulative Update 7
  • Microsoft Exchange Server 2019 Cumulative Update 8

✅ Remediation

KB4602269 (Security Update)

🔗 References (5)