Дата обнаружения
|
09/11/2021 |
Уровень угрозы
|
High |
Описание
|
Multiple vulnerabilities were found in Microsoft Exchange Server. Malicious users can exploit these vulnerabilities to perform cross-site scripting attack, execute arbitrary code, spoof user interface. Below is a complete list of vulnerabilities:
|
Эксплуатация
|
The following public exploits exists for this vulnerability: https://github.com/timb-machine-mirrors/testanull-CVE-2021-42321_poc.py Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details. |
Пораженные продукты
|
Microsoft Exchange Server 2019 Cumulative Update 10 |
Решение
|
Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel) |
Первичный источник обнаружения
|
CVE-2021-41349 CVE-2021-42321 CVE-2021-42305 |
Оказываемое влияние
?
|
ACE
[?]
XSS/CSS
[?]
SUI
[?]
|
Связанные продукты
|
Microsoft Exchange Server |
CVE-IDS
|
|
KB list
|