CVE-2021-28481: Microsoft Exchange Server Remote Code Execution Vulnerability
Published Apr 13, 2021
·Updated
Microsoft Exchange Server Remote Code Execution Vulnerability
Affected Software
5 affected components
Microsoft Exchange Server=2013-cumulative_update_23
Microsoft Exchange Server=2016-cumulative_update_19
Microsoft Exchange Server=2016-cumulative_update_20
Microsoft Exchange Server=2019-cumulative_update_8
Microsoft Exchange Server=2019-cumulative_update_9
Remediation
Event History
Apr 13, 2021
CVE Published
07:33 PM
Data Sourced
07:33 PM
DescriptionSeverity
Mar 26, 2024
News Published
via ZDNet·06:57 PM
News Published
via ZDNet·07:48 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2021-28481?
CVE-2021-28481 is classified as a critical remote code execution vulnerability.
2
What versions of Microsoft Exchange Server are affected by CVE-2021-28481?
CVE-2021-28481 affects Microsoft Exchange Server versions 2013, 2016, and 2019 with specific cumulative updates.
3
How do I fix CVE-2021-28481?
To mitigate CVE-2021-28481, apply the latest security updates provided by Microsoft.
4
What is the impact of exploiting CVE-2021-28481?
Exploitation of CVE-2021-28481 can allow an attacker to execute arbitrary code on the affected Microsoft Exchange Server.
5
Is there a workaround for CVE-2021-28481?
There are no official workarounds for CVE-2021-28481, so applying the security updates is essential.