This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Exchange Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Autodiscover service. The issue results from the lack of proper validation of URI prior to accessing resources. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of SYSTEM.
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
ZDI-21-821 has a critical severity rating due to its potential for remote code execution without authentication.
To fix ZDI-21-821, apply the latest security updates from Microsoft for Exchange Server.
ZDI-21-821 affects unpatched installations of Microsoft Exchange Server that utilize the Autodiscover service.
ZDI-21-821 is a remote code execution vulnerability that allows attackers to execute arbitrary code on the affected systems.
No, authentication is not required to exploit the vulnerability identified in ZDI-21-821.