CRITICAL

CVE-2021-34523

Microsoft Exchange Server 2021-07-14 CVSS v3.1
CVSS
9
KEV

Description

Microsoft Exchange Server Elevation of Privilege Vulnerability

Summary dbcve.org

This is an elevation of privilege vulnerability in Microsoft Exchange Server. The CVSS score of 9 (Critical) indicates severe security impact, typically meaning an authenticated attacker can gain higher-level permissions or execute code with elevated privileges on the affected Exchange server.

Mitigation

Apply Microsoft security updates/patches for Exchange Server immediately. If patches cannot be applied immediately, implement compensating controls such as restricting access to Exchange services, enabling MFA for admin accounts, and monitoring for indicators of compromise.

Proof of Concept
Patch Commit

EPSS Score

99.99%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE