PT-2021-3816 · Microsoft · Exchange Server

·

CVE-2021-34523

·

Published

2021-07-13

·

Updated

2026-07-07

CVSS v3.1

9.0

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server (affected versions not specified)
Description An elevation of privilege issue exists in Microsoft Exchange Server. This flaw allows an attacker to increase their privilege level on the system. Additionally, improper authentication in PowerShell may lead to remote code execution, which allows an attacker to execute arbitrary commands on the server from a remote location.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04126
CVE-2021-34523
ZDI-21-822

Affected Products

Exchange Server