CVE-2021-33766
Microsoft Exchange Server Information Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
YesDecision
Descriptions
Microsoft Exchange Server Information Disclosure Vulnerability
Una vulnerabilidad de Divulgación de Información de Microsoft Exchange
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Exchange Server. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the authentication of requests to web services within the ecp web application. By issuing a crafted request, an attacker can bypass authentication. An attacker can leverage this vulnerability to disclose information from the server.
Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-05-28 CVE Reserved
- 2021-07-14 CVE Published
- 2021-09-15 First Exploit
- 2022-01-18 Exploited in Wild
- 2022-02-01 KEV Due Date
- 2024-08-03 CVE Updated
- 2024-10-15 EPSS Updated
CWE
- CWE-287: Improper Authentication
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://www.zerodayinitiative.com/advisories/ZDI-21-798 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/bhdresh/CVE-2021-33766 | 2021-10-14 | |
https://github.com/demossl/CVE-2021-33766-ProxyToken | 2021-09-15 |
URL | Date | SRC |
---|---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-33766 | 2024-07-24 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2013 Search vendor "Microsoft" for product "Exchange Server" and version "2013" | cumulative_update_23 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2016 Search vendor "Microsoft" for product "Exchange Server" and version "2016" | cumulative_update_19 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2016 Search vendor "Microsoft" for product "Exchange Server" and version "2016" | cumulative_update_20 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2019 Search vendor "Microsoft" for product "Exchange Server" and version "2019" | cumulative_update_8 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2019 Search vendor "Microsoft" for product "Exchange Server" and version "2019" | cumulative_update_9 |
Affected
|