CVE-2021-24085HighCVSS 6.5
Microsoft Exchange Server Spoofing Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What is the nature of the spoofing? An authenticated attacker can leak a cert file which results in a CSRF token to be generated.
🎯 Affected products4
- Microsoft Exchange Server 2016 Cumulative Update 18
- Microsoft Exchange Server 2016 Cumulative Update 19
- Microsoft Exchange Server 2019 Cumulative Update 7
- Microsoft Exchange Server 2019 Cumulative Update 8
✅ Remediation
KB4602269 (Security Update)
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-24085
- patchhttps://www.microsoft.com/download/details.aspx?familyid=1a27365b-3ef6-4755-a2de-9733c1107efc
- referencehttps://support.microsoft.com/help/4602269
- patchhttp://www.microsoft.com/download/details.aspx?familyid=7dd6bd46-9bf2-4b1b-a7ed-69221f8225a9
- patchhttp://www.microsoft.com/download/details.aspx?familyid=543dff06-10b4-4c99-b8ab-17cecbd95c33