PT-2021-3816 · Microsoft · Exchange Server

Orangetw

·

Published

2021-07-13

·

Updated

2026-05-20

·

CVE-2021-34523

CVSS v3.1

9.0

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server versions 2013 through 2019
Description The issue is related to errors in privilege management, allowing an attacker to elevate their privileges. This can affect the system and potentially lead to remote code execution due to improper authentication in Microsoft Exchange Server's PowerShell.
Recommendations For Microsoft Exchange Server versions 2013 through 2019, consider restricting access to the PowerShell module to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider disabling the vulnerable authentication mechanism in the PowerShell interface until a fix is provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04126
CVE-2021-34523
ZDI-21-822

Affected Products

Exchange Server