First published: Tue Apr 13 2021(Updated: )
Microsoft Exchange Server Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
=2013-cumulative_update_23 | ||
=2016-cumulative_update_19 | ||
=2016-cumulative_update_20 | ||
=2019-cumulative_update_8 | ||
=2019-cumulative_update_9 | ||
Microsoft Exchange Server | =2013-cumulative_update_23 | |
Microsoft Exchange Server | =2016-cumulative_update_19 | |
Microsoft Exchange Server | =2016-cumulative_update_20 | |
Microsoft Exchange Server | =2019-cumulative_update_8 | |
Microsoft Exchange Server | =2019-cumulative_update_9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-28483 is classified as a critical remote code execution vulnerability.
To mitigate CVE-2021-28483, apply the latest cumulative updates provided by Microsoft for affected versions of Exchange Server.
CVE-2021-28483 affects Microsoft Exchange Server versions 2013, 2016, and 2019, specifically certain cumulative updates.
Exploitation of CVE-2021-28483 can allow an attacker to execute arbitrary code on the affected Exchange Server.
It is recommended to apply the patch as the most effective solution, but implementing strict firewall rules may help reduce exposure temporarily.