PT-2021-3816 · Microsoft · Exchange Server
Orangetw
·
Published
2021-07-13
·
Updated
2026-05-20
·
CVE-2021-34523
CVSS v3.1
9.0
Critical
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Exchange Server versions 2013 through 2019
Description
The issue is related to errors in privilege management, allowing an attacker to elevate their privileges. This can affect the system and potentially lead to remote code execution due to improper authentication in Microsoft Exchange Server's PowerShell.
Recommendations
For Microsoft Exchange Server versions 2013 through 2019, consider restricting access to the PowerShell module to minimize the risk of exploitation until a patch is available.
As a temporary workaround, consider disabling the vulnerable authentication mechanism in the PowerShell interface until a fix is provided.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Exchange Server