CVE-2021-28480CriticalCVSS 9.8

Microsoft Exchange Server Remote Code Execution Vulnerability

Published
April 13, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Where can I find more information about protecting myself from this vulnerability? Please see the MSRC Blog Post April 2021 Update Tuesday packages now available for more information.

🎯 Affected products5

  • Microsoft Exchange Server 2013 Cumulative Update 23
  • Microsoft Exchange Server 2016 Cumulative Update 19
  • Microsoft Exchange Server 2016 Cumulative Update 20
  • Microsoft Exchange Server 2019 Cumulative Update 8
  • Microsoft Exchange Server 2019 Cumulative Update 9

✅ Remediation

KB5001779 (Security Update) — fixed build 15.00.1497.015 KB5001779 (Security Update) — fixed build 15.01.2176.012 KB5001779 (Security Update) — fixed build 15.02.0792.013 KB5001779 (Security Update) — fixed build 15.01.2242.008 KB5001779 (Security Update) — fixed build 15.02.0858.010

🔗 References (7)