PT-2021-2211 · Microsoft · Exchange Server

Published

2021-03-02

·

Updated

2026-05-04

·

CVE-2021-27065

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server versions 2013, 2016, and 2019
Description This issue in Microsoft Exchange Server allows remote attackers to execute arbitrary code. The root cause is insufficient input validation. Exploitation may allow an attacker to overwrite arbitrary files within the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2021-01120
CVE-2021-27065

Affected Products

Exchange Server