CVE-2021-34523
Microsoft Exchange Server Privilege Escalation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
YesDecision
Descriptions
Microsoft Exchange Server Elevation of Privilege Vulnerability
Una vulnerabilidad de ElevaciĆ³n de Privilegios de Microsoft Exchange Server. Este ID de CVE es diferente de CVE-2021-33768, CVE-2021-34470
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Exchange Server. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
The specific flaw exists within the Powershell service. The issue results from the lack of proper validation of a access token prior to executing the Exchange PowerShell command. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of SYSTEM.
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-06-09 CVE Reserved
- 2021-07-14 CVE Published
- 2021-11-03 Exploited in Wild
- 2021-11-17 KEV Due Date
- 2023-09-02 First Exploit
- 2024-08-04 CVE Updated
- 2024-11-16 EPSS Updated
CWE
- CWE-287: Improper Authentication
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://www.zerodayinitiative.com/advisories/ZDI-21-822 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/SUPRAAA-1337/CVE-2021-34523 | 2023-09-02 | |
http://packetstormsecurity.com/files/163895/Microsoft-Exchange-ProxyShell-Remote-Code-Execution.html | 2024-08-04 |
URL | Date | SRC |
---|---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34523 | 2024-02-13 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2013 Search vendor "Microsoft" for product "Exchange Server" and version "2013" | cumulative_update_23 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2016 Search vendor "Microsoft" for product "Exchange Server" and version "2016" | cumulative_update_19 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2016 Search vendor "Microsoft" for product "Exchange Server" and version "2016" | cumulative_update_20 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2019 Search vendor "Microsoft" for product "Exchange Server" and version "2019" | cumulative_update_8 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2019 Search vendor "Microsoft" for product "Exchange Server" and version "2019" | cumulative_update_9 |
Affected
|