First published: Tue May 11 2021(Updated: )
Microsoft Exchange Server Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2013-cumulative_update_23 | |
Microsoft Exchange Server | =2016-cumulative_update_19 | |
Microsoft Exchange Server | =2016-cumulative_update_20 | |
Microsoft Exchange Server | =2019-cumulative_update_8 | |
Microsoft Exchange Server | =2019-cumulative_update_9 | |
Microsoft Exchange |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31198 is a vulnerability in Microsoft Exchange Server that allows remote attackers to execute arbitrary code on affected installations.
CVE-2021-31198 has a severity rating of 8.8 (high).
CVE-2021-31198 affects Microsoft Exchange Server 2013 Cumulative Update 23, 2016 Cumulative Update 19 and 20, and 2019 Cumulative Update 8 and 9.
CVE-2021-31198 can be exploited by bypassing the existing authentication mechanism and exploiting the flaw in the OAB service.
You can find more information about CVE-2021-31198 on the Microsoft Security Response Center (MSRC) website and the Zero Day Initiative (ZDI) website.