CVE-2024-21410: Microsoft Exchange Server Privilege Escalation Vulnerability
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
Other sources
Microsoft Exchange Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.2.1544.004Patch KB5035606 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.037Patch KB5036386
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-21410?
CVE-2024-21410 has been classified as a critical elevation of privilege vulnerability in Microsoft Exchange Server.
How do I fix CVE-2024-21410?
To fix CVE-2024-21410, install the latest security updates from Microsoft for the affected versions of Exchange Server.
Which versions of Microsoft Exchange Server are affected by CVE-2024-21410?
CVE-2024-21410 affects Microsoft Exchange Server 2016 and 2019, specifically cumulative updates 13 and 14 for 2019 and cumulative update 23 for 2016.
What type of vulnerability is CVE-2024-21410?
CVE-2024-21410 is an elevation of privilege vulnerability which allows attackers to gain elevated access to system resources.
Is there a known exploit for CVE-2024-21410?
Yes, CVE-2024-21410 is reported to be exploited in the wild as a zero-day vulnerability.