CVE-2021-27065

Summary

Microsoft Exchange Server Remote Code Execution Vulnerability

Affected Software

VendorProductVersion RangeStatus
MicrosoftMicrosoft Exchange Server 2013 Cumulative Update 2115.00.0 < 15.00.1395.012affected
MicrosoftMicrosoft Exchange Server 2013 Cumulative Update 2215.00.0 < 15.00.1473.006affected
MicrosoftMicrosoft Exchange Server 2013 Cumulative Update 2315.00.0 < 15.00.1497.012affected
MicrosoftMicrosoft Exchange Server 2013 Service Pack 115.00.0 < 15.00.0847.064affected
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 1015.01.0 < 15.01.1531.012affected
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 1115.01.0 < 15.01.1591.018affected
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 1215.01.0 < 15.01.1713.010affected
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 1315.01.0 < 15.01.1779.008affected
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 1415.01.0 < 15.01.1847.012affected
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 1515.01.0 < 15.01.1913.012affected
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 1615.01.0 < 15.01.1979.008affected
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 1715.01.0 < 15.01.2044.013affected
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 1815.01.0 < 15.01.2106.013affected
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 1915.01.0 < 15.01.2176.009affected
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 815.01.0 < 15.01.1415.010affected
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 915.01.0 < 15.01.1466.016affected
MicrosoftMicrosoft Exchange Server 201915.02.0 < 15.02.0221.018affected
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 115.02.0 < 15.01.1979.006affected
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 215.02.0 < 15.02.0397.011affected
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 315.02.0 < 15.02.0464.015affected
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 415.02.0 < 15.02.0659.012affected
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 515.02.0 < 15.02.0595.008affected
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 615.02.0 < 15.02.0529.013affected
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 715.02.0 < 15.02.0721.013affected
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 815.02.0 < 15.02.0792.010affected

Weaknesses

  • Remote Code Execution

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: active
    • Automatable: yes
    • Technical Impact: total

Additional References

References