CVE-2021-31206HighCVSS 7.6
Microsoft Exchange Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Was this vulnerability found in the 2021 Pwn2Own contest? Yes, this was one of the Exchange Server vulnerabilities found in the 2021 Pwn2Own contest.
🎯 Affected products5
- Microsoft Exchange Server 2013 Cumulative Update 23
- Microsoft Exchange Server 2016 Cumulative Update 20
- Microsoft Exchange Server 2016 Cumulative Update 21
- Microsoft Exchange Server 2019 Cumulative Update 10
- Microsoft Exchange Server 2019 Cumulative Update 9
✅ Remediation
KB5004780 (Security Update) — fixed build 15.02.0858.015 KB5004779 (Security Update) — fixed build 15.01.2242.012 KB5004778 (Security Update) — fixed build 15.00.1497.023 KB5004779 (Security Update) — fixed build 15.01.2308.014 KB5004780 (Security Update) — fixed build 15.02.0922.013
🔗 References (9)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-31206
- patchhttp://www.microsoft.com/download/details.aspx?familyid=a78de9ec-af4e-4e31-be7d-17db9fc335db
- referencehttps://support.microsoft.com/help/5004780
- patchhttp://www.microsoft.com/download/details.aspx?familyid=61d75c2f-8b98-4971-b22c-ebd114772d3d
- referencehttps://support.microsoft.com/help/5004779
- patchhttp://www.microsoft.com/download/details.aspx?familyid=cae731a5-0d00-4f76-b2c6-84bd511e529f
- referencehttps://support.microsoft.com/help/5004778
- patchhttp://www.microsoft.com/download/details.aspx?familyid=ccf40c19-2653-4b5c-b922-d6d09bbf1c3e
- patchhttp://www.microsoft.com/download/details.aspx?familyid=07683b40-1608-437d-a90a-eb2683cb3092