CVE-2021-33766: Microsoft Exchange Server Information Disclosure
Microsoft Exchange Information Disclosure Vulnerability
Other sources
Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.
— CISA
Microsoft Exchange Server Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-33766?
CVE-2021-33766 is a vulnerability that allows remote attackers to disclose sensitive information on affected installations of Microsoft Exchange Server.
How severe is CVE-2021-33766?
CVE-2021-33766 has a severity rating of 7.5, which is considered high.
What software is affected by CVE-2021-33766?
Microsoft Exchange Server 2013, 2016, and 2019 are affected by CVE-2021-33766.
Do I need authentication to exploit CVE-2021-33766?
No, authentication is not required to exploit CVE-2021-33766.
How can I fix CVE-2021-33766?
To fix CVE-2021-33766, apply the relevant patches provided by Microsoft or follow the recommended remediation steps available on their support website.