CVE-2021-34470Improper Privilege Management in Microsoft Exchange Server 2013 Cumulative Update 23

Severity
8.0HIGHNVD
EPSS
4.7%
top 10.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 14
Latest updateMay 24

Description

Microsoft Exchange Server Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.1 | Impact: 5.9

Affected Packages4 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-hxhm-28wc-v3qm: Microsoft Exchange Server Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-33768, CVE-2021-345232022-05-24
CVEList
Microsoft Exchange Server Elevation of Privilege Vulnerability2021-07-14
VulnCheck
Microsoft Exchange Server Privilege Escalation2021

📋Vendor Advisories

1
Microsoft
Microsoft Exchange Server Elevation of Privilege Vulnerability2021-07-13
CVE-2021-34470 — Improper Privilege Management | cvebase