cbcvebase.
CVE-2021-33768
published 2021-07-14

CVE-2021-33768: Microsoft Exchange Server Elevation of Privilege Vulnerability

PriorityP278high8CVSS 3.1
AVAACLPRLUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
1.16%
63.6th percentile
Microsoft Exchange Server Elevation of Privilege Vulnerability

Affected

10 ranges
VendorProductVersion rangeFixed in
microsoftexchange_server
microsoftexchange_server
microsoftmicrosoft_exchange_server_2016_cumulative_update_20>= 15.01.0 < 15.01.2242.01215.01.2242.012
microsoftmicrosoft_exchange_server_2016_cumulative_update_21>= 15.01.0 < 15.01.2308.01415.01.2308.014
microsoftmicrosoft_exchange_server_2019_cumulative_update_10>= 15.02.0 < 15.02.0922.01315.02.0922.013
microsoftmicrosoft_exchange_server_2019_cumulative_update_9>= 15.02.0 < 15.02.0858.01515.02.0858.015
msrcmicrosoft_exchange_server_2016_cumulative_update_20
msrcmicrosoft_exchange_server_2016_cumulative_update_21
msrcmicrosoft_exchange_server_2019_cumulative_update_10
msrcmicrosoft_exchange_server_2019_cumulative_update_9

Detection & IOCsextracted from sources · hover to see the quote

  • Attack vector is Adjacent (AV:A), meaning exploitation requires the attacker to be on the same logical or physical network segment as the target Exchange Server — not exploitable directly over the open internet.
  • Exploitation requires man-in-the-middle type setup or prior foothold in an adjacent network environment; monitor for anomalous lateral movement or ARP/network spoofing activity targeting Exchange Server hosts.
  • Impact is Elevation of Privilege on Microsoft Exchange Server; monitor Exchange Server processes and service accounts for unexpected privilege escalation events.
  • ·Exploit status is 'Exploitation Less Likely' for both latest and older software releases, and has not been publicly disclosed or exploited in the wild as of the advisory date.

CVSS provenance

nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.2MEDIUMAV:A/AC:L/Au:S/C:P/I:P/A:P
vulncheck8.0HIGH
vendor_msrc8.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.