CVE-2021-42321: Microsoft Exchange Server Remote Code Execution Vulnerability
An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
Other sources
Microsoft Exchange Server Remote Code Execution Vulnerability
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-42321?
CVE-2021-42321 is a vulnerability in Microsoft Exchange Server that allows an authenticated attacker to perform remote code execution.
How does CVE-2021-42321 affect Microsoft Exchange Server?
CVE-2021-42321 affects Microsoft Exchange Server versions 2016 Cumulative Update 21, 2016 Cumulative Update 22, 2019 Cumulative Update 10, and 2019 Cumulative Update 11.
What is the severity of CVE-2021-42321?
CVE-2021-42321 has a severity rating of 8.8 (high).
How can an attacker exploit CVE-2021-42321?
An authenticated attacker can exploit CVE-2021-42321 by leveraging improper validation in cmdlet arguments within Microsoft Exchange to perform remote code execution.
Is there a fix available for CVE-2021-42321?
Yes, Microsoft has released security updates to address CVE-2021-42321. It is recommended to apply the latest Cumulative Updates for the affected versions of Microsoft Exchange Server.