Input validation error in Microsoft Exchange Server - CVE-2021-42321
Published: November 9, 2021 / Updated: November 16, 2022
Vulnerability details
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to insufficient validation of cmdlet arguments. A remote user can run a specially crafted cmdlet and execute arbitrary commands on the system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2021-42321
Links to Public Exploits and PoC-codes
- Exploit #8613 - exch_CVE-2021-42321 () (November 16, 2022)
- Exploit #8267 - Microsoft Exchange Server ChainedSerializationBinder RCE (August 19, 2022)
- Exploit #7772 - Microsoft Exchange Server ChainedSerializationBinder Deny List Typo RCE (May 12, 2022)
- Exploit #7224 - CVE-2021-42321_poc () (January 6, 2022)