CVE-2021-26412: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.0721.013Patch KB5000871 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2106.013Patch KB5000871 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2176.009Patch KB5000871 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.0792.010Patch KB5000871 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.00.1497.012Patch KB5000871
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26412?
CVE-2021-26412 has been rated as critical due to its potential for remote code execution.
How do I fix CVE-2021-26412?
To fix CVE-2021-26412, apply the latest security updates provided by Microsoft for your version of Exchange Server.
What are the affected versions listed under CVE-2021-26412?
CVE-2021-26412 affects Microsoft Exchange Server 2013 CU23, 2016 CU18 and CU19, and 2019 CU7 and CU8.
Can CVE-2021-26412 be exploited remotely?
Yes, CVE-2021-26412 can be exploited remotely without authentication, making it particularly dangerous.
Are there any known exploits for CVE-2021-26412?
Yes, there are known exploits in the wild that target CVE-2021-26412, emphasizing the urgency to apply patches.