Junglewise Threat Intelligence

CVE-2024-21410: Microsoft Exchange Server Privilege Escalation Vulnerability

CVE-2024-21410 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-02-15

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server contains an elevation of privilege vulnerability due to improper authentication. The flaw allows a remote, unauthenticated attacker to escalate privileges on the system. This vulnerability has been confirmed to be exploited in the wild.

Affected products

  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server 2019 Cumulative Update 13
  • Microsoft Exchange Server 2019 Cumulative Update 14

Timeline

  • 2024-02-13: disclosed: Initial disclosure by Microsoft Corporation
  • 2024-02-15: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog
  • 2024-03-07: other: CISA due date for required mitigation action

Related threats