Junglewise Threat Intelligence

CVE-2021-42321: Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2021-42321 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-17

Technologies: Microsoft Exchange Server 2019, Microsoft Exchange Server 2016. Vendors: Microsoft.

Executive brief

An authenticated remote code execution vulnerability exists in Microsoft Exchange Server due to improper validation of cmdlet arguments. An attacker with low privileges can exploit this flaw to execute arbitrary code on the server.

Affected products

  • Microsoft Exchange Server 2016 Cumulative Update 21, Cumulative Update 22
  • Microsoft Exchange Server 2019 Cumulative Update 10, Cumulative Update 11

Timeline

  • 2021-11-09: disclosed: NVD Published Date
  • 2021-11-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-17: advisory: MSRC advisory published/updated
  • 2021-11-17: exploited: Reported as exploited in the wild