Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2021-27065

Опубликовано: 10 мар. 2021
Источник: msrc
CVSS3: 7.8
EPSS Критический

Описание

Microsoft Exchange Server Remote Code Execution Vulnerability

Меры по смягчению последствий

This vulnerability is part of an attack chain. The initial attack requires the ability to make an untrusted connection to Exchange server port 443. This can be protected against by restricting untrusted connections, or by setting up a VPN to separate the Exchange server from external access. Using this mitigation will only protect against the initial portion of the attack. Other portions of the chain can be triggered if an attacker already has access or can convince an administrator to open a malicious file.

We recommend prioritizing installing updates on Exchange Servers that are externally facing.

FAQ

Is this vulnerability being used in an active attack?

Yes. The vulnerability described in this CVE is one of four vulnerabilities that are being exploited in an active attack. The security updates address this attack. More information can be found here: https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server.

What is the target for this attack?

The initial attack in this attack chain targets an Exchange On-prem server that is able to receive untrusted connections from an external source. In addition, the Exchange server would need to be running Microsoft Exchange Server 2013, 2016, or 2019.

Where can I get more information about how to protect myself from the vulnerabilities?

Please see On-Premises Exchange Server Vulnerabilities Resource Center – updated March 25, 2021.

If I install the Security Updates for the older Cumulative Updates, am I fully protected from vulnerabilities for all published CVEs?

No, you will be protected from the vulnerabilities documented by CVE-2021-27065, CVE-2021-26855, CVE-2021-26857, CVE-2021-26858. You will not be protected from some previous CVEs as shown in the table below.

  • Yes: the system is protected from the vulnerability.
  • No: the system is not protected from the vulnerability.

Microsoft Exchange Server 2019

Date ReleasedSeverityCVEES 2019 CU8ES 2019 CU7ES 2019 CU6ES 2019 CU5ES 2019 CU4ES 2019 CU3ES 2019 CU2ES 2019 CU1ES 2019
8/14/2018CriticalCVE-2018-8302YesYesYesYesYesYesYesYesNo
10/9/2018ImportantCVE-2018-8448YesYesYesYesYesYesYesYesNo
11/13/2018ImportantCVE-2018-8581YesYesYesYesYesYesYesNoNo
12/11/2018ImportantCVE-2018-8604YesYesYesYesYesYesYesNoNo
1/8/2019ImportantCVE-2019-0586YesYesYesYesYesYesYesNoNo
1/8/2019ImportantCVE-2019-0588YesYesYesYesYesYesYesNoNo
2/12/2019ImportantCVE-2019-0686YesYesYesYesYesYesYesNoNo
2/12/2019ImportantCVE-2019-0724YesYesYesYesYesYesYesNoNo
9/10/2019ImportantCVE-2019-1233YesYesYesYesYesYesNoNoNo
10/19/2019ImportantCVE-2019-1266YesYesYesYesYesNoNoNoNo
11/12/2019CriticalCVE-2019-1373YesYesYesYesYesNoNoNoNo
2/11/2020ImportantCVE-2020-0688YesYesYesYesNoNoNoNoNo
2/11/2020ImportantCVE-2020-0692YesYesYesYesNoNoNoNoNo
3/10/2020ImportantCVE-2020-0903YesYesYesYesNoNoNoNoNo
9/8/2020CriticalCVE-2020-16875YesYesNoNoNoNoNoNoNo
10/13/2020ImportantCVE-2020-16969YesYesNoNoNoNoNoNoNo
11/10/2020ImportantCVE-2020-17083YesYesNoNoNoNoNoNoNo
11/10/2020ImportantCVE-2020-17084YesYesNoNoNoNoNoNoNo
11/10/2020ImportantCVE-2020-17085YesYesNoNoNoNoNoNoNo
12/8/2020CriticalCVE-2020-17117YesYesNoNoNoNoNoNoNo
12/8/2020CriticalCVE-2020-17132YesYesNoNoNoNoNoNoNo
12/8/2020ImportantCVE-2020-17141YesYesNoNoNoNoNoNoNo
12/8/2020CriticalCVE-2020-17142YesYesNoNoNoNoNoNoNo
12/8/2020ImportantCVE-2020-17143YesYesNoNoNoNoNoNoNo
12/8/2020ImportantCVE-2020-17144YesYesNoNoNoNoNoNoNo
2/9/2021ImportantCVE-2021-1730YesYesNoNoNoNoNoNoNo
2/9/2021ImportantCVE-2021-24085YesYesNoNoNoNoNoNoNo
3/2/2021ImportantCVE-2021-26412YesYesNoNoNoNoNoNoNo
3/2/2021ImportantCVE-2021-26854YesYesNoNoNoNoNoNoNo

Microsoft Exchange Server 2016

Date ReleasedSeverityCVEES 2016 CU19ES 2016 CU18ES 2016 CU16ES 2016 CU15ES 2016 CU14ES 2016 CU17ES 2016 CU13ES 2016 CU12ES 2016 CU11ES 2016 CU10ES 2016 CU9ES 2016 CU8
3/13/2018ImportantCVE-2018-0940YesYesYesYesYesYesYesYesYesYesYesNo
3/13/2018ImportantCVE-2018-0941YesYesYesYesYesYesYesYesYesYesYesNo
4/3/2018CriticalCVE-2018-0986YesYesYesYesYesYesYesYesYesYesNoNo
5/8/2018ImportantCVE-2018-8151YesYesYesYesYesYesYesYesYesYesNoNo
5/8/2018ImportantCVE-2018-8152YesYesYesYesYesYesYesYesYesYesNoNo
5/8/2018CriticalCVE-2018-8154YesYesYesYesYesYesYesYesYesYesNoNo
5/8/2018ImportantCVE-2018-8159YesYesYesYesYesYesYesYesYesYesNoNo
10/9/2018ImportantCVE-2018-8265YesYesYesYesYesYesYesYesYesNoNoNo
8/14/2018CriticalCVE-2018-8302YesYesYesYesYesYesYesYesYesNoNoNo
10/9/2018ImportantCVE-2018-8448YesYesYesYesYesYesYesYesNoNoNoNo
11/13/2018ImportantCVE-2018-8581YesYesYesYesYesYesYesYesNoNoNoNo
12/11/2018ImportantCVE-2018-8604YesYesYesYesYesYesYesYesNoNoNoNo
1/8/2019ImportantCVE-2019-0586YesYesYesYesYesYesYesYesNoNoNoNo
1/8/2019ImportantCVE-2019-0588YesYesYesYesYesYesYesYesNoNoNoNo
2/12/2019ImportantCVE-2019-0686YesYesYesYesYesYesYesYesNoNoNoNo
2/12/2019ImportantCVE-2019-0724YesYesYesYesYesYesYesYesNoNoNoNo
4/9/2019ImportantCVE-2019-0817YesYesYesYesYesYesYesNoNoNoNoNo
4/9/2019ImportantCVE-2019-0858YesYesYesYesYesYesYesNoNoNoNoNo
7/9/2019ImportantCVE-2019-1084YesYesYesYesYesYesNoNoNoNoNoNo
7/9/2019ImportantCVE-2019-1136YesYesYesYesYesYesNoNoNoNoNoNo
7/9/2019ImportantCVE-2019-1137YesYesYesYesYesYesNoNoNoNoNoNo
9/10/2019ImportantCVE-2019-1233YesYesYesYesYesYesNoNoNoNoNoNo
10/19/2019ImportantCVE-2019-1266YesYesYesYesNoYesNoNoNoNoNoNo
11/12/2019CriticalCVE-2019-1373YesYesYesYesNoYesNoNoNoNoNoNo
2/11/2020ImportantCVE-2020-0688YesYesYesYesNoYesNoNoNoNoNoNo
2/11/2020ImportantCVE-2020-0692YesYesYesYesNoYesNoNoNoNoNoNo
3/10/2020ImportantCVE-2020-0903YesYesYesYesNoYesNoNoNoNoNoNo
9/8/2020CriticalCVE-2020-16875YesYesNoNoNoNoNoNoNoNoNoNo
10/13/2020ImportantCVE-2020-16969YesYesNoNoNoNoNoNoNoNoNoNo
11/10/2020ImportantCVE-2020-17083YesYesNoNoNoNoNoNoNoNoNoNo
11/10/2020ImportantCVE-2020-17084YesYesNoNoNoNoNoNoNoNoNoNo
11/10/2020ImportantCVE-2020-17085YesYesNoNoNoNoNoNoNoNoNoNo
12/8/2020CriticalCVE-2020-17117YesYesNoNoNoNoNoNoNoNoNoNo
12/8/2020CriticalCVE-2020-17132YesYesNoNoNoNoNoNoNoNoNoNo
12/8/2020ImportantCVE-2020-17141YesYesNoNoNoNoNoNoNoNoNoNo
12/8/2020CriticalCVE-2020-17142YesYesNoNoNoNoNoNoNoNoNoNo
12/8/2020ImportantCVE-2020-17143YesYesNoNoNoNoNoNoNoNoNoNo
12/8/2020ImportantCVE-2020-17144YesYesNoNoNoNoNoNoNoNoNoNo
2/9/2021ImportantCVE-2021-1730YesYesNoNoNoNoNoNoNoNoNoNo
2/9/2021ImportantCVE-2021-24085YesYesNoNoNoNoNoNoNoNoNoNo
3/2/2021ImportantCVE-2021-26412YesYesNoNoNoNoNoNoNoNoNoNo
3/2/2021ImportantCVE-2021-26854YesYesNoNoNoNoNoNoNoNoNoNo
  • Microsoft Exchange Server 2013 CU 22 was released February 12, 2019 after which 31 vulnerabilities have been found and remediated.
  • Microsoft Exchange Server 2013 CU 21 was released June 19, 2018 after which 38 vulnerabilities have been found and remediated.
  • Microsoft Exchange Server 2013 Service Pack 1 was released February 25, 2014 after which 82 vulnerabilities have been found and remediated.

Please see Exchange Server build numbers and release dates for more information on Exchange Server Cumulative Updates release dates.

Обновления

ПродуктСтатьяОбновление
Microsoft Exchange Server 2013 Service Pack 1
Microsoft Exchange Server 2016 Cumulative Update 8
Microsoft Exchange Server 2016 Cumulative Update 9
Microsoft Exchange Server 2013 Cumulative Update 21
Microsoft Exchange Server 2016 Cumulative Update 10
Microsoft Exchange Server 2019
Microsoft Exchange Server 2016 Cumulative Update 11
Microsoft Exchange Server 2013 Cumulative Update 22
Microsoft Exchange Server 2016 Cumulative Update 12
Microsoft Exchange Server 2019 Cumulative Update 1

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

Yes

Latest Software Release

Exploitation Detected

Older Software Release

Exploitation Detected

DOS

N/A

EPSS

Процентиль: 100%
0.94366
Критический

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
больше 4 лет назад

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS3: 7.8
github
около 3 лет назад

Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27078.

CVSS3: 8.8
fstec
больше 4 лет назад

Уязвимость почтового сервера Microsoft Exchange Server, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю перезаписать произвольные файлы в системе

CVSS3: 7.8
msrc
больше 4 лет назад

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS3: 7.8
msrc
больше 4 лет назад

Microsoft Exchange Server Remote Code Execution Vulnerability

EPSS

Процентиль: 100%
0.94366
Критический

7.8 High

CVSS3