Microsoft Exchange Server Remote Code Execution Vulnerability
High CVSS 8.8 Listed in CISA KEV
Summary
An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Microsoft:Exchange
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2021-42321 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42321 Patch
- http://packetstormsecurity.com/files/166153/Microsoft-Exchange-Server-Remote-Code-Execution.html Exploit
- http://packetstormsecurity.com/files/168131/Microsoft-Exchange-Server-ChainedSerializationBinder-Remote-Code-Execution.html Exploit
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42321 Patch
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-42321 US Government Resource
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD