CISA Known Exploited Vulnerability

CVE-2021-33766

Microsoft · Exchange Server

Microsoft Exchange Server Information Disclosure

Date added
BOD 22-01 due date
CWE CWE-287
Ransomware Unknown

CISA description

Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.

Required action

Apply updates per vendor instructions.