Microsoft Exchange Server 2019 Cumulative Update 7 vulnerabilities

18 known vulnerabilities affecting microsoft/microsoft_exchange_server_2019_cumulative_update_7.

Total CVEs
18
CISA KEV
4
actively exploited
Public exploits
2
Exploited in wild
4
Severity breakdown
CRITICAL3HIGH10MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2021-26855CRITICALCVSS 9.8KEVPoC≥ 15.02.0, < publication2021-03-03
CVE-2021-26855 [CRITICAL] CWE-918 CVE-2021-26855: Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2021-27078HIGHCVSS 7.2≥ 15.02.0, < publication2021-03-03
CVE-2021-27078 [CRITICAL] CVE-2021-27078: Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2021-26857HIGHCVSS 7.8KEV≥ 15.02.0, < publication2021-03-03
CVE-2021-26857 [HIGH] CWE-502 CVE-2021-26857: Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2021-26412HIGHCVSS 7.2≥ 15.02.0, < publication2021-03-03
CVE-2021-26412 [CRITICAL] CVE-2021-26412: Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2021-26854HIGHCVSS 7.2≥ 15.02.0, < publication2021-03-03
CVE-2021-26854 [MEDIUM] CVE-2021-26854: Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2021-27065HIGHCVSS 7.8KEVPoC≥ 15.02.0, < publication2021-03-03
CVE-2021-27065 [HIGH] CWE-22 CVE-2021-27065: Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2021-26858HIGHCVSS 7.8KEV≥ 15.02.0, < publication2021-03-03
CVE-2021-26858 [HIGH] CVE-2021-26858: Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2021-1730MEDIUMCVSS 5.4≥ 15.02.0, < publication2021-02-25
CVE-2021-1730 [MEDIUM] CVE-2021-1730: <p>A spoofing vulnerability exists in Microsoft Exchange Server which could result in an attack that A spoofing vulnerability exists in Microsoft Exchange Server which could result in an attack that would allow a malicious actor to impersonate the user. This update addresses this vulnerability. To prevent these types of attacks, Microsoft recommends customers to download inline images from different DNSdomains than the rest of OWA. Please see further instruc
cvelistv5nvd
CVE-2021-24085MEDIUMCVSS 6.5≥ 15.02.0, < publication2021-02-25
CVE-2021-24085 [MEDIUM] Microsoft Exchange Server Spoofing Vulnerability Microsoft Exchange Server Spoofing Vulnerability Microsoft Exchange Server Spoofing Vulnerability
cvelistv5
CVE-2020-17132CRITICALCVSS 9.1≥ 15.02.0, < publication2020-12-10
CVE-2020-17132 [CRITICAL] CVE-2020-17132: Microsoft Exchange Remote Code Execution Vulnerability Microsoft Exchange Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2020-17142CRITICALCVSS 9.1≥ 15.02.0, < publication2020-12-10
CVE-2020-17142 [CRITICAL] CVE-2020-17142: Microsoft Exchange Remote Code Execution Vulnerability Microsoft Exchange Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2020-17117HIGHCVSS 7.2≥ 15.02.0, < publication2020-12-10
CVE-2020-17117 [MEDIUM] CVE-2020-17117: Microsoft Exchange Remote Code Execution Vulnerability Microsoft Exchange Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2020-17141HIGHCVSS 8.4≥ 15.02.0, < publication2020-12-10
CVE-2020-17141 [HIGH] CVE-2020-17141: Microsoft Exchange Remote Code Execution Vulnerability Microsoft Exchange Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2020-17143HIGHCVSS 8.8≥ 15.02.0, < publication2020-12-10
CVE-2020-17143 [HIGH] CVE-2020-17143: Microsoft Exchange Server Information Disclosure Vulnerability Microsoft Exchange Server Information Disclosure Vulnerability
cvelistv5nvd
CVE-2020-17084HIGHCVSS 8.8≥ 15.02.0, < publication2020-11-11
CVE-2020-17084 [HIGH] CWE-120 CVE-2020-17084: Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2020-17083MEDIUMCVSS 5.4≥ 15.02.0, < publication2020-11-11
CVE-2020-17083 [MEDIUM] CWE-79 CVE-2020-17083: Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2020-17085MEDIUMCVSS 4.9≥ 15.02.0, < publication2020-11-11
CVE-2020-17085 [MEDIUM] CVE-2020-17085: Microsoft Exchange Server Denial of Service Vulnerability Microsoft Exchange Server Denial of Service Vulnerability
cvelistv5nvd
CVE-2020-16969MEDIUMCVSS 6.5≥ 15.02.0, < publication2020-10-16
CVE-2020-16969 [HIGH] CVE-2020-16969: <p>An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when ha An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user. To exploit the vulnerability, an attacker could include specially crafted OWA messages that could be loaded, without warning o
cvelistv5nvd