CVE-2021-31207MediumCVSS 6.6

Microsoft Exchange Server Security Feature Bypass Vulnerability

Published
May 11, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Was this vulnerability found in the 2021 Pwn2Own contest? Yes, this was one of the Exchange Server vulnerabilities found in the 2021 Pwn2Own contest.

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.

🎯 Affected products5

  • Microsoft Exchange Server 2013 Cumulative Update 23
  • Microsoft Exchange Server 2016 Cumulative Update 19
  • Microsoft Exchange Server 2016 Cumulative Update 20
  • Microsoft Exchange Server 2019 Cumulative Update 8
  • Microsoft Exchange Server 2019 Cumulative Update 9

✅ Remediation

KB5003435 (Security Update) — fixed build 15.00.1497.018 KB5003435 (Security Update) — fixed build 15.02.0858.012 KB5003435 (Security Update) — fixed build 15.01.2242.010 KB5003435 (Security Update) — fixed build 15.01.2176.014 KB5003435 (Security Update) — fixed build 15.02.0792.015

🔗 References (7)