Junglewise Threat Intelligence

CVE-2021-26858: Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2021-26858 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server contains a remote code execution vulnerability that is part of the ProxyLogon exploit chain. The flaw allows an attacker to execute arbitrary code on the server, though CVSS metrics indicate a local attack vector with user interaction required.

Affected products

  • Microsoft Exchange Server 2010 SP3, 2013 SP1, 2013 CU22, 2013 CU23, 2016 CU8-CU19, 2019 CU1-CU8

Timeline

  • 2021-03-02: disclosed: Initial disclosure of ProxyLogon vulnerabilities
  • 2021-03-08: other: Initial analysis by NIST
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats