HIGH
CVE-2021-42321
CVSS
8.8
KEV
Description
Microsoft Exchange Server Remote Code Execution Vulnerability
Summary dbcve.org
Microsoft Exchange Server contains a remote code execution vulnerability that allows an attacker to execute arbitrary code on the target server. The high CVSS score of 8.8 indicates network-based exploitation with relatively low complexity.
Mitigation
Apply Microsoft security updates for CVE-2021-42321 to Exchange Server immediately. If patching is not immediately possible, implement network-level restrictions to limit exposure to untrusted networks.
EPSS Score
91.74%
Probability of exploitation in next 30 days
99.8th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42321
Patch, Vendor Advisory
http://packetstormsecurity.com/files/166153/Microsoft-Exchange-Server-Remote-Code-Execution.html
Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/168131/Microsoft-Exchange-Server-ChainedSerializationBinder-Remote-Code-Execution.html
Exploit, Third Party Advisory, VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42321
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-42321
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.