Microsoft Calls for Immediate Patching of Vulnerability in Exchange Server
A severe vulnerability in Exchange Server 2016 and Exchange Server 2019 is currently being actively exploited. As a result, Microsoft calls for immediate action.
It is a post-authentication vulnerability in Exchange 2016 and 2019 and allows remote code execution due to incorrect validation of cmdlet arguments. Users in Exchange Hybrid mode are also vulnerable. However, exchange Online users do not. The vulnerability can be found as CVE-2021-42321.
Microsoft says the vulnerability is currently being actively exploited, albeit to a limited extent.
In a blog post on the vulnerabilities this month, explains more, including information about how companies can update and how to use the Exchange Server Health Checker script to check which Exchange Servers have not installed the latest updates.