CVE-2021-33766HighCVSS 7.3
Microsoft Exchange Server Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is Personally Identifiable Information (PII).
🎯 Affected products5
- Microsoft Exchange Server 2013 Cumulative Update 23
- Microsoft Exchange Server 2016 Cumulative Update 19
- Microsoft Exchange Server 2016 Cumulative Update 20
- Microsoft Exchange Server 2019 Cumulative Update 8
- Microsoft Exchange Server 2019 Cumulative Update 9
✅ Remediation
KB5001779 (Security Update) — fixed build 15.02.0858.010 KB5001779 (Security Update) — fixed build 15.01.2242.008 KB5001779 (Security Update) — fixed build 15.00.1497.015 KB5001779 (Security Update) — fixed build 15.01.2176.012 KB5001779 (Security Update) — fixed build 15.02.0792.013
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-33766
- patchhttp://www.microsoft.com/download/details.aspx?familyid=5aa2aaf7-860d-4977-acd4-82096c83c5f0
- referencehttps://support.microsoft.com/help/5001779
- patchhttp://www.microsoft.com/download/details.aspx?familyid=b13f23a9-5603-4b13-8e16-6d35b5b33524
- patchhttp://www.microsoft.com/download/details.aspx?familyid=f827ff3b-194c-4470-aa8f-6cedc0d95d07
- patchhttp://www.microsoft.com/download/details.aspx?familyid=52da6d67-e0c4-4af0-a133-1e47217b6309
- patchhttp://www.microsoft.com/download/details.aspx?familyid=93809dc0-0265-4116-bc51-510ce641008b