Lucene search

K
kasperskyKaspersky LabKLA12103
HistoryMar 02, 2021 - 12:00 a.m.

KLA12103 ACE vulnerabilities in Microsoft Exchange Server

2021-03-0200:00:00
Kaspersky Lab
threats.kaspersky.com
479

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

9.6 High

AI Score

Confidence

High

0.975 High

EPSS

Percentile

100.0%

Remote code execution vulnerabilities were found in Microsoft Exchange Server. Malicious users can exploit this vulnerability to execute arbitrary code.

Original advisories

CVE-2021-26412

CVE-2021-26855

CVE-2021-27078

CVE-2021-27065

CVE-2021-26854

CVE-2021-26857

CVE-2021-26858

Exploitation

This vulnerability can be exploited by the following malware:

https://threats.kaspersky.com/en/threat/Exploit.Script.CVE-2021-26855/

Public exploits exist for this vulnerability.

Related products

Microsoft-Exchange-Server

CVE list

CVE-2021-26412 critical

CVE-2021-26855 critical

CVE-2021-27078 critical

CVE-2021-27065 critical

CVE-2021-26854 high

CVE-2021-26857 critical

CVE-2021-26858 critical

KB list

5000871

5000978

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

Affected Products

  • Microsoft Exchange Server 2019 Cumulative Update 8Microsoft Exchange Server 2013 Cumulative Update 23Microsoft Exchange Server 2016 Cumulative Update 18Microsoft Exchange Server 2010 Service Pack 3Microsoft Exchange Server 2016 Cumulative Update 19Microsoft Exchange Server 2019 Cumulative Update 7

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

9.6 High

AI Score

Confidence

High

0.975 High

EPSS

Percentile

100.0%