CVE-2021-42321HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .9174 99.8 YES
AFFECTED Product Versions Fixed Microsoft Exchange Server 2016 Cumulative Update 21 15.01.0 – — Microsoft Exchange Server 2016 Cumulative Update 22 15.0.0 – — Microsoft Exchange Server 2019 Cumulative Update 10 15.02.0 – — Microsoft Exchange Server 2019 Cumulative Update 11 15.02.0 – —
TIMELINE Oct 12 Reserved by microsoft Nov 17 Added to CISA KEV, remediation due 2021-12-01 Nov 17 Published (CNA: microsoft) Aug 19 EXPLOIT PUBLISHED — CVE-2021-42321 (Microsoft Exchange Server 2016 Cumulative Update 21). Public exploit reference added.
CNA: microsoft · CVSS v3.1 · 5 references · NVD status: Analyzed · KEV due December 1, 2021