Executive brief
Microsoft Exchange Server contains a remote code execution vulnerability involving improper limitation of a pathname to a restricted directory (path traversal). This vulnerability is a component of the ProxyLogon exploit chain and has been observed being exploited in the wild.
Affected products
- Microsoft Exchange Server 2013 Cumulative Update 21, 22, 23, Service Pack 1
- Microsoft Exchange Server 2016 Cumulative Update 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19
- Microsoft Exchange Server 2019 Cumulative Update 1, 2, 4, 5, 6, 7, 8
Timeline
- 2021-11-03: disclosed: Published date in advisory
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-04-16: other: Original due date for remediation in CISA KEV record