VDB
BDU%3A2021-04285
BDU%3A2021-04285
PUBLISHED
CVSS 7.300000190734863 HIGH
Уязвимость почтового сервера Microsoft Exchange Server, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Risk Scores
CVSS 3.1
7.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft Exchange Server 2016 Cumulative Update 19 | 15.01.0 |
| Microsoft | Microsoft Exchange Server 2013 Cumulative Update 23 | 15.00.0 |
| Microsoft Corp | Microsoft Exchange Server | |
| Microsoft | Microsoft Exchange Server 2019 Cumulative Update 8 | 15.02.0 |
| Microsoft | Microsoft Exchange Server 2016 Cumulative Update 20 | 15.01.0 |
| Microsoft | Microsoft Exchange Server 2019 Cumulative Update 9 | 15.02.0 |
Timeline
- Apr 13, 2021 PoC Published
- Sep 1, 2021 CVE Published
- Sep 23, 2021 PoC Published
- Jun 14, 2023 PoC Published
- Oct 21, 2023 PoC Published
- Dec 11, 2023 PoC Published
- Mar 1, 2024 PoC Published
- Apr 5, 2024 PoC Published
- Jul 14, 2024 PoC Published
- Jul 17, 2024 PoC Published
- Sep 24, 2024 CVE Updated
- Oct 8, 2024 PoC Published
References
- https://www.cisa.gov/sites/default/files/csv/known_exploited_vulnerabilities.csv url
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-33766 url
- https://www.zerodayinitiative.com/advisories/ZDI-21-798/ url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-33766 url
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-33766 url
- https://www.zerodayinitiative.com/blog/2021/8/30/proxytoken-an-authentication-bypass-in-microsoft-exchange-server url