CISA Known Exploited Vulnerability

CVE-2021-42321 Ransomware

Microsoft · Exchange

Microsoft Exchange Server Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-184, CWE-502
Ransomware Known

CISA description

An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.

Required action

Apply updates per vendor instructions.