CRITICAL
CVE-2021-34523
CVSS
9
KEV
Description
Microsoft Exchange Server Elevation of Privilege Vulnerability
Summary dbcve.org
This is an elevation of privilege vulnerability in Microsoft Exchange Server. The CVSS score of 9 (Critical) indicates severe security impact, typically meaning an authenticated attacker can gain higher-level permissions or execute code with elevated privileges on the affected Exchange server.
Mitigation
Apply Microsoft security updates/patches for Exchange Server immediately. If patches cannot be applied immediately, implement compensating controls such as restricting access to Exchange services, enabling MFA for admin accounts, and monitoring for indicators of compromise.
EPSS Score
99.99%
Probability of exploitation in next 30 days
100th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34523
Patch, Vendor Advisory
http://packetstormsecurity.com/files/163895/Microsoft-Exchange-ProxyShell-Remote-Code-Execution.html
Exploit, Third Party Advisory, VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34523
Patch, Vendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-21-822/
Third Party Advisory, VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-34523
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.