CVE-2021-42321CISA KEV
Microsoft Exchange Server Remote Code Execution Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
- Product
- Exchange
- Added to KEV
- 17 Nov 2021
- Federal remediation due
- 1 Dec 2021
- Known ransomware use
- Yes