9.8
CVE-2021-34523
- EPSS 94.02%
- Veröffentlicht 14.07.2021 18:15:12
- Zuletzt bearbeitet 07.03.2025 17:12:53
- Quelle secure@microsoft.com
- Teams Watchlist Login
- Unerledigt Login
Microsoft Exchange Server Elevation of Privilege Vulnerability
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Exchange Server Version2013 Updatecumulative_update_23
Microsoft ≫ Exchange Server Version2016 Updatecumulative_update_19
Microsoft ≫ Exchange Server Version2016 Updatecumulative_update_20
Microsoft ≫ Exchange Server Version2019 Updatecumulative_update_8
Microsoft ≫ Exchange Server Version2019 Updatecumulative_update_9
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Exchange Server Privilege Escalation Vulnerability
SchwachstelleMicrosoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
BeschreibungApply updates per vendor instructions.
Erforderliche MaßnahmenTyp | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 94.02% | 0.999 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
secure@microsoft.com | 9 | 2.5 | 5.8 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
|