#VU51169 Input validation error in Microsoft Exchange Server - CVE-2021-26858
Published: March 2, 2021 / Updated: April 1, 2021
Microsoft Exchange Server
Microsoft
Description
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send specially crafted data to the Exchange server and execute arbitrary code on the system.
Note, this vulnerability is being actively exploited in the wild.