Executive brief
Microsoft Exchange Server contains a security feature bypass vulnerability due to unrestricted upload of files with dangerous types (CWE-434). This vulnerability is part of the 'ProxyShell' exploit chain and allows an authenticated attacker with high privileges to bypass security restrictions.
Affected products
- Microsoft Exchange Server 2013 Cumulative Update 23
- Microsoft Exchange Server 2016 Cumulative Update 19, Cumulative Update 20
- Microsoft Exchange Server 2019 Cumulative Update 8, Cumulative Update 9
Timeline
- 2021-05-11: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild in the advisory summary and CISA KEV catalog.