Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Exchange Server.
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-21410CRITICAL | Microsoft Exchange Server Elevation of Privilege VulnerabilityMicrosoft Exchange Server Elevation of Privilege Vulnerability CWE-287Feb 13, 2024 | CVSS9.8v3.1 | EPSS12.7% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-36745HIGH | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability CWE-502Sep 12, 2023 | CVSS8.0v3.1 | EPSS81.1% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21529HIGH | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability CWE-502Feb 14, 2023 | CVSS8.8v3.1 | EPSS62.1% | PoCs0 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2022-41080HIGH | Microsoft Exchange Server Elevation of Privilege VulnerabilityMicrosoft Exchange Server Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-41123. Nov 9, 2022 | CVSS8.8v3.1 | EPSS77.3% | PoCs2 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2022-41082HIGH | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability. CWE-502Oct 3, 2022 | CVSS8.0v3.1 | EPSS>99.9% | PoCs13 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2022-41040HIGH | Microsoft Exchange Server Elevation of Privilege VulnerabilityMicrosoft Exchange Server Elevation of Privilege Vulnerability. | CVSS8.8v3.1 | EPSS>99.9% | PoCs10 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2022-24463MEDIUM | Microsoft Exchange Server Spoofing VulnerabilityMicrosoft Exchange Server Spoofing Vulnerability. Mar 9, 2022 | CVSS6.5v3.1 | EPSS31.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-42321HIGH | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability | CVSS8.8v3.1 | EPSS90.4% | PoCs3 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2021-41349MEDIUM | Microsoft Exchange Server Spoofing VulnerabilityMicrosoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-42305. Nov 10, 20211 related artifact | CVSS6.5v3.1 | EPSS93.9% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-34523CRITICAL | Microsoft Exchange Server Elevation of Privilege VulnerabilityMicrosoft Exchange Server Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-33768, CVE-2021-34470. | CVSS9.0v3.1 | EPSS>99.9% | PoCs5 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2021-34473CRITICAL | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31196, CVE-2021-31206. | CVSS9.1v3.1 | EPSS>99.9% | PoCs14 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2021-34470HIGH | Microsoft Exchange Server Elevation of Privilege VulnerabilityMicrosoft Exchange Server Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-33768, CVE-2021-34523. CWE-269Jul 14, 2021 | CVSS8.0v3.1 | EPSS4.38% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-33768HIGH | Microsoft Exchange Server Elevation of Privilege VulnerabilityMicrosoft Exchange Server Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-34470, CVE-2021-34523. CWE-269Jul 14, 2021 | CVSS8.0v3.1 | EPSS1.29% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-33766HIGH | Microsoft Exchange Server Information Disclosure VulnerabilityMicrosoft Exchange Information Disclosure Vulnerability | CVSS7.3v3.1 | EPSS98.2% | PoCs2 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-31206HIGH | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31196, CVE-2021-34473. Jul 14, 2021 | CVSS7.6v3.1 | EPSS13% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2021-31196HIGH | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31206, CVE-2021-34473. Jul 14, 2021 | CVSS7.2v3.1 | EPSS54.1% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-31207MEDIUM | Microsoft Exchange Server Security Feature Bypass VulnerabilityMicrosoft Exchange Server Security Feature Bypass Vulnerability | CVSS6.6v3.1 | EPSS99.8% | PoCs3 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2021-28482HIGH | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-28480, CVE-2021-28481, CVE-2021-28483. Apr 13, 2021 | CVSS8.8v3.1 | EPSS83.2% | PoCs2 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2021-28481CRITICAL | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-28480, CVE-2021-28482, CVE-2021-28483. Apr 13, 20211 related artifact | CVSS9.8v3.1 | EPSS36.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-27065HIGH | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27078. | CVSS7.8v3.1 | EPSS>99.9% | PoCs17 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2021-26858HIGH | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-27065, CVE-2021-27078. Mar 2, 2021 | CVSS7.8v3.1 | EPSS89.5% | PoCs7 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2021-26857HIGH | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078. | CVSS7.8v3.1 | EPSS94% | PoCs9 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2021-26855CRITICAL | Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078. | CVSS9.1v3.1 | EPSS>99.9% | PoCs56 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2020-17144HIGH | Microsoft Exchange Remote Code Execution Vulnerability, aka 'Microsoft Exchange Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-17117, CVE-2020-17132, CVE-2020-17141, CVE-2020-17142. | CVSS8.4v3.1 | EPSS36.5% | PoCs2 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-16875HIGH | Microsoft Exchange Server Remote Code Execution VulnerabilityA remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user, aka 'Microsoft Exchange Server Remote Code Execution Vulnerability'. | CVSS8.4v3.1 | EPSS47.4% | PoCs1 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |