CVE-2021-42321HighCVSS 8.8
Microsoft Exchange Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Where can I find more information about this vulnerability? Please see Exchange Blog regarding the details of this Exchange release.
According to the CVSS metric, privileges required is low (PR:L). Does the attacker need to be in an authenticated role on the Exchange Server? Yes, the attacker must be authenticated.
🎯 Affected products4
- Microsoft Exchange Server 2016 Cumulative Update 21
- Microsoft Exchange Server 2016 Cumulative Update 22
- Microsoft Exchange Server 2019 Cumulative Update 10
- Microsoft Exchange Server 2019 Cumulative Update 11
✅ Remediation
KB5007409 (Security Update) — fixed build 15.01.2308.020 KB5007409 (Security Update) — fixed build 15.02.0792.019 KB5007409 (Security Update) — fixed build 15.01.2375.017 KB5007409 (Security Update) — fixed build 15.02.0986.014
🔗 References (6)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42321
- patchhttp://www.microsoft.com/download/details.aspx?familyid=de4b96e0-8d0e-4830-8354-7ed2128e6f82
- referencehttps://support.microsoft.com/help/5007409
- patchhttp://www.microsoft.com/download/details.aspx?familyid=1c42658f-9d60-4afb-a6c6-e35594b17d39
- patchhttp://www.microsoft.com/download/details.aspx?familyid=688b79c6-7e43-4332-848d-47e88f60818c
- patchhttp://www.microsoft.com/download/details.aspx?familyid=cd28ac6e-eb6f-4747-b9f0-24785b08a012