Security restrictions bypass in Microsoft Exchange Server - CVE-2021-26427

 

Security restrictions bypass in Microsoft Exchange Server - CVE-2021-26427

Published: October 12, 2021


Vulnerability identifier: #VU57255
CSH Severity: Medium
CVSS v4: 9.4 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2021-26427
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions. A remote user on the local network can send specially crafted data to the Exchange server and execute arbitrary code with elevated privileges.


Affected software

Microsoft Exchange Server

How to mitigate CVE-2021-26427

Install updates from vendor's website.


External References

Related Security Bulletins