← back
CVE-2021-34473

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 9.1 CRITICALEPSS 100.0%● KEVCWE-918
In short

A critical flaw in Microsoft Exchange Server allows attackers to execute arbitrary code remotely without authentication. This affects email servers worldwide and can lead to complete system compromise.

Technical detail

Server-Side Request Forgery (SSRF) vulnerability in Exchange Server's Autodiscover service allows unauthenticated attackers to bypass authentication mechanisms and achieve Remote Code Execution through malicious requests. The vulnerability enables execution of arbitrary PowerShell commands with System privileges, requiring only network access to the affected server.

Summary generated and translated by AI from the official description.
Microsoft Exchange Server Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →