CVE-2021-34470High· 8.0▾ MidnightPoC availableMicrosoft Exchange Server Elevation of Privilege Vulnerability
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 44 · likelihood 0.9 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
3.3%
3.3% → 4.4%
1 GitHub repo
Microsoft Exchange Server Elevation of Privilege Vulnerability
exchange_server = 2013exchange_server = 2016exchange_server = 2019Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-42321High· 8.8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-27065High· 7.8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26857High· 7.8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26855Critical· 9.1Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-34523Critical· 9.0Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2021-34473Critical· 9.1Microsoft Exchange Server Remote Code Execution Vulnerability