packetstormsecurity.com
http://packetstormsecurity.com/files/166153/Microsoft-Exchange-Server-Remote-Code-Execution.html CVE-2021-42321
HIGHCISA KEVRansomware
Microsoft Exchange Server Remote Code Execution Vulnerability
Record summary
CVE-2021-42321 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit and 2 repository PoCs. CISA lists CVE-2021-42321 in KEV and reports its use in known ransomware campaigns.
Description
Microsoft Exchange Server Remote Code Execution Vulnerability
Description source: GitHub Advisory
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 17, 2021 · CISA
- VulnCheck KEV
- Listed · Nov 9, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · CISA
Available material
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 3, 2024 · Source: CVE List
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
ExchangeBrowse Microsoft / Exchange | CISA | Version data not supplied | |
Exchange ServerBrowse Microsoft / Exchange Server | VulnCheck | Version data not supplied | |
Microsoft Exchange Server 2016 Cumulative Update 21Browse Microsoft / Microsoft Exchange Server 2016 Cumulative Update 21 | CVE List | 15.01.0 to < 15.01.2308.020 | affected |
Microsoft Exchange Server 2016 Cumulative Update 22Browse Microsoft / Microsoft Exchange Server 2016 Cumulative Update 22 | CVE List | 15.0.0 to < 15.01.2375.017 | affected |
Microsoft Exchange Server 2019 Cumulative Update 10Browse Microsoft / Microsoft Exchange Server 2019 Cumulative Update 10 | CVE List | 15.02.0 to < 15.02.0792.019 | affected |
Microsoft Exchange Server 2019 Cumulative Update 11Browse Microsoft / Microsoft Exchange Server 2019 Cumulative Update 11 | CVE List | 15.02.0 to < 15.02.0986.014 | affected |
Proofs of concept
3Catalogued exploits
MetasploitMicrosoft Exchange Server ChainedSerializationBinder RCEMetasploit exploitby Grant Willcox +8 moreNot analyzed1 file
Repository PoCs
GitHubDarkSprings/CVE-2021-42321Repository PoCby DarkSpringsStars: 83Not analyzed2 files
GitHub7BitsTeam/exch_CVE-2021-42321Repository PoCby 7BitsTeamStars: 10Not analyzed3 files
References
5packetstormsecurity.com
http://packetstormsecurity.com/files/168131/Microsoft-Exchange-Server-ChainedSerializationBinder-Remote-Code-Execution.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-42321 portal.msrc.microsoft.com
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42321 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-42321