<< Back
CVE Number Vulnerability Product Severity Date
CVE-2021-28481 Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server 2019 Critical 23-04-2021

Technical Information

Brief overview of the risk:

An unauthenticated remote code execution vulnerability which is wormable exists in Microsoft Exchange Servers. This bug was identified by the National Security Agency. An attacker who successfully exploited the vulnerability could execute arbitrary code in the context of the logged on user.

Further information on this vulnerability is available at : CVE-2021-28481

Affected Software

Microsoft Exchange Server 2019 Cumulative Update 9
Microsoft Exchange Server 2016 Cumulative Update 20
Microsoft Exchange Server 2013 Cumulative Update 23
Microsoft Exchange Server 2016 Cumulative Update 19
Microsoft Exchange Server 2019 Cumulative Update 8