Security restrictions bypass in Microsoft Exchange Server - CVE-2021-26427
Published: October 12, 2021
Vulnerability identifier: #VU57255
CSH Severity: Medium
CVSS v4: 9.4 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2021-26427
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions. A remote user on the local network can send specially crafted data to the Exchange server and execute arbitrary code with elevated privileges.
Affected software
Microsoft Exchange Server
How to mitigate CVE-2021-26427
Install updates from vendor's website.