Junglewise Threat Intelligence

CVE-2021-34523: Microsoft Exchange Server Privilege Escalation Vulnerability

CVE-2021-34523 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server contains an elevation of privilege vulnerability, part of the 'ProxyShell' exploit chain. The flaw allows an unauthenticated attacker to escalate privileges on affected installations. This vulnerability has been observed being exploited in the wild.

Affected products

  • Microsoft Exchange Server 2013 Cumulative Update 23
  • Microsoft Exchange Server 2016 Cumulative Update 19
  • Microsoft Exchange Server 2016 Cumulative Update 20
  • Microsoft Exchange Server 2019 Cumulative Update 8
  • Microsoft Exchange Server 2019 Cumulative Update 9

Timeline

  • 2021-07-14: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-17: patched: CISA due date for remediation

Related threats