CVE-2021-42321
Description
Microsoft Exchange Server Remote Code Execution Vulnerability
In plain language
AI Act nowCVE-2021-42321 lets an attacker run arbitrary code on Microsoft Exchange Server over the network with little effort—if you run Exchange Server, this is a serious risk and you should act now.
CVE-2021-42321 is a remote code execution vulnerability in Microsoft Exchange Server that can be triggered over the network with low required authentication; it has been used in ransomware campaigns (CISA KEV), so affected organizations must apply Microsoft’s Exchange Server updates immediately.
What to do now
- Check which Microsoft Exchange Server version/cumulative update you are running.
- Compare your current Exchange Server update level against the fixed versions: 2016 CU21 (fixed in 15.01.2308.020), 2016 CU22 (fixed in 15.01.2375.017), 2019 CU10 (fixed in 15.02.0792.019), 2019 CU11 (fixed in 15.02.0986.014).
- Upgrade/patch Exchange Server to the corresponding fixed version for your current CU level (or to the latest available Exchange Server security update that supersedes it).
- After patching, verify Exchange services are healthy and that the server is reachable only through approved network paths; review Exchange and server logs for suspicious activity tied to remote requests.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2021-42321 and every CVE in our database. Create a free account — no credit card required.
Create Free Account