First published: Tue Feb 13 2024(Updated: )
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | ||
Microsoft Exchange Server | =2016-cumulative_update_23 | |
Microsoft Exchange Server | =2019-cumulative_update_13 | |
Microsoft Exchange Server | =2019-cumulative_update_14 | |
Microsoft Exchange Server | =23 | |
Microsoft Exchange Server | =14 | |
Microsoft Exchange Server | =13 | |
Microsoft Exchange Server | =23 |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-21410 has been classified as a critical elevation of privilege vulnerability in Microsoft Exchange Server.
To fix CVE-2024-21410, install the latest security updates from Microsoft for the affected versions of Exchange Server.
CVE-2024-21410 affects Microsoft Exchange Server 2016 and 2019, specifically cumulative updates 13 and 14 for 2019 and cumulative update 23 for 2016.
CVE-2024-21410 is an elevation of privilege vulnerability which allows attackers to gain elevated access to system resources.
Yes, CVE-2024-21410 is reported to be exploited in the wild as a zero-day vulnerability.