CVE-2021-28483: Microsoft Exchange Server Remote Code Execution Vulnerability
Published Apr 13, 2021
·Updated
Microsoft Exchange Server Remote Code Execution Vulnerability
Affected Software
5 affected components
Microsoft Exchange Server=2013-cumulative_update_23
Microsoft Exchange Server=2016-cumulative_update_19
Microsoft Exchange Server=2016-cumulative_update_20
Microsoft Exchange Server=2019-cumulative_update_8
Microsoft Exchange Server=2019-cumulative_update_9
Remediation
Event History
Apr 13, 2021
CVE Published
07:33 PM
Data Sourced
07:33 PM
DescriptionSeverity
Mar 26, 2024
News Published
via ZDNet·06:57 PM
News Published
via ZDNet·07:48 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2021-28483?
CVE-2021-28483 is classified as a critical remote code execution vulnerability.
2
How do I fix CVE-2021-28483?
To mitigate CVE-2021-28483, apply the latest cumulative updates provided by Microsoft for affected versions of Exchange Server.
3
What versions of Microsoft Exchange Server are affected by CVE-2021-28483?
CVE-2021-28483 affects Microsoft Exchange Server versions 2013, 2016, and 2019, specifically certain cumulative updates.
4
What are the potential impacts of exploiting CVE-2021-28483?
Exploitation of CVE-2021-28483 can allow an attacker to execute arbitrary code on the affected Exchange Server.
5
Is there a workaround for CVE-2021-28483 before patching?
It is recommended to apply the patch as the most effective solution, but implementing strict firewall rules may help reduce exposure temporarily.