6.5
CVE-2021-31207
- EPSS 99.78%
- Veröffentlicht 11.05.2021 19:15:10
- Zuletzt bearbeitet 30.10.2025 19:40:19
- Erkennungen
Microsoft Exchange Server Security Feature Bypass Vulnerability
Microsoft Exchange Server Security Feature Bypass Vulnerability
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Exchange Server Version 2013 Update cumulative_update_23
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_19
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_20
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_8
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_9
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Exchange Server Security Feature Bypass Vulnerability
SchwachstelleMicrosoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 99.78% | 1 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
| NIST | 6.6 | 0.7 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| Microsoft | 6.6 | 0.7 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
http://packetstormsecurity.com/files/163895/Microsoft-Exchange-ProxyShell-Remote-Code-Execution.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31207
https://www.zerodayinitiative.com/advisories/ZDI-21-819/
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-31207