Code Injection in Microsoft Exchange Server - CVE-2021-28483

 

Code Injection in Microsoft Exchange Server - CVE-2021-28483

Published: April 13, 2021 / Updated: October 15, 2024


Vulnerability identifier: #VU52141
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28483
CWE-ID: CWE-94
Exploitation vector: Adjecent network
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation in the Microsoft Exchange Server. A remote authenticated attacker on the local network can send a specially crafted request and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Microsoft Exchange Server

How to mitigate CVE-2021-28483

Install updates from vendor's website.

Microsoft Exchange Server - addressed in versions 2013 Cumulative Update 23 Apr21SU 15.00.1497.015, 2016 Cumulative Update 19 Apr21SU 15.01.2176.012, 2016 Cumulative Update 20 Apr21SU 15.01.2242.008, 2019 Cumulative Update 8 Apr21SU 15.02.0792.013, 2019 Cumulative Update 9 Apr21SU 15.02.0858.010

External References

Related Security Bulletins