6.6
CVE-2021-31207
- EPSS 93.87%
- Veröffentlicht 11.05.2021 19:15:10
- Zuletzt bearbeitet 13.03.2025 16:41:49
- Quelle secure@microsoft.com
- Teams Watchlist Login
- Unerledigt Login
Microsoft Exchange Server Security Feature Bypass Vulnerability
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Exchange Server Version2013 Updatecumulative_update_23
Microsoft ≫ Exchange Server Version2016 Updatecumulative_update_19
Microsoft ≫ Exchange Server Version2016 Updatecumulative_update_20
Microsoft ≫ Exchange Server Version2019 Updatecumulative_update_8
Microsoft ≫ Exchange Server Version2019 Updatecumulative_update_9
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Exchange Server Security Feature Bypass Vulnerability
SchwachstelleMicrosoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
BeschreibungApply updates per vendor instructions.
Erforderliche MaßnahmenTyp | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 93.87% | 0.999 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
nvd@nist.gov | 6.6 | 0.7 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
|
secure@microsoft.com | 6.6 | 0.7 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.