First published: Wed Jul 14 2021(Updated: )
Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.
Credit: secure@microsoft.com secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2013-cumulative_update_23 | |
Microsoft Exchange Server | =2016-cumulative_update_20 | |
Microsoft Exchange Server | =2016-cumulative_update_21 | |
Microsoft Exchange Server | =2019-cumulative_update_10 | |
Microsoft Exchange Server | =2019-cumulative_update_9 | |
Microsoft Exchange Server |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31196 is a remote code execution vulnerability in Microsoft Exchange Server.
The severity of CVE-2021-31196 is high with a severity value of 7.2.
Microsoft Exchange Server 2013 Cumulative Update 23, 2016 Cumulative Update 20 and 21, and 2019 Cumulative Update 9 and 10 are affected by CVE-2021-31196.
To fix the CVE-2021-31196 vulnerability, apply the latest security updates provided by Microsoft for the affected versions of Microsoft Exchange Server.
You can find more information about CVE-2021-31196 in the Microsoft Security Guidance Advisory for CVE-2021-31196.