目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2021-41349— Microsoft Exchange Server 安全漏洞

CVSS 6.5 · Medium EPSS 93.88% · P100

Public Exploits 1

新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2021-41349の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Microsoft Exchange Server Spoofing Vulnerability
ソース: CVE Program / CVE List V5
脆弱性説明
Microsoft Exchange Server Spoofing Vulnerability
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Microsoft Exchange Server 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Microsoft Exchange Server是美国微软(Microsoft)公司的一套电子邮件服务程序。它提供邮件存取、储存、转发,语音邮件,邮件过滤筛选等功能。 Microsoft Exchange Server存在安全漏洞。以下产品和版本受到影响:Microsoft Exchange Server 2013 Cumulative Update 23,Microsoft Exchange Server 2016 Cumulative Update 21,Microsoft Exchange Ser
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

Shenlong 10 Questions — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
MicrosoftMicrosoft Exchange Server 2013 Cumulative Update 23 15.00.0 ~ 15.00.1497.026 cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:*
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 21 15.01.0 ~ 15.01.2308.020 cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_21:*:*:*:*:*:*
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 10 15.02.0 ~ 15.02.0792.019 cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_10:*:*:*:*:*:*
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 22 15.0.0 ~ 15.01.2375.017 cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_22:*:*:*:*:*:*
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 11 15.02.0 ~ 15.02.0986.014 cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_11:*:*:*:*:*:*

II. CVE-2021-41349の公開POC

#POC説明ソースリンクShenlongリンク
1Exploiting: CVE-2021-41349https://github.com/exploit-io/CVE-2021-41349POC詳細
2Microsoft Exchange Server Spoofing Vulnerability Exploit!https://github.com/0xrobiul/CVE-2021-41349POC詳細
3Microsoft Exchange Server is vulnerable to a spoofing vulnerability. Be aware this CVE ID is unique from CVE-2021-42305.https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-41349.yamlPOC詳細
4exchange反射型xss漏洞https://github.com/chaitin/xray-plugins/blob/main/poc/manual/exchange-cve-2021-41349-xss.ymlPOC詳細
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2021-41349のインテリジェンス情報

登录查看更多情报信息。

CVE-2021-41349 厂商安全公告 (1)

Same Patch Batch · Microsoft · 2021-11-10 · 54 CVEs total

CVE-2021-264439.0 CRITICALMicrosoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
CVE-2021-386668.8 HIGHRemote Desktop Client Remote Code Execution Vulnerability
CVE-2021-423218.8 HIGHMicrosoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-423168.8 HIGHMicrosoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
CVE-2021-422838.8 HIGHNTFS Elevation of Privilege Vulnerability
CVE-2021-422758.8 HIGHMicrosoft COM for Windows Remote Code Execution Vulnerability
CVE-2021-422967.8 HIGHMicrosoft Word Remote Code Execution Vulnerability
CVE-2021-432087.8 HIGH3D Viewer Remote Code Execution Vulnerability
CVE-2021-422987.8 HIGHMicrosoft Defender Remote Code Execution Vulnerability
CVE-2021-432097.8 HIGH3D Viewer Remote Code Execution Vulnerability
CVE-2021-422867.8 HIGHWindows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege
CVE-2021-422857.8 HIGHWindows Kernel Elevation of Privilege Vulnerability
CVE-2021-422767.8 HIGHMicrosoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2021-413787.8 HIGHWindows NTFS Remote Code Execution Vulnerability
CVE-2021-413777.8 HIGHWindows Fast FAT File System Driver Elevation of Privilege Vulnerability
CVE-2021-413707.8 HIGHNTFS Elevation of Privilege Vulnerability
CVE-2021-413677.8 HIGHNTFS Elevation of Privilege Vulnerability
CVE-2021-413667.8 HIGHCredential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerabili
CVE-2021-404427.8 HIGHMicrosoft Excel Remote Code Execution Vulnerability
CVE-2021-369577.8 HIGHWindows Desktop Bridge Elevation of Privilege Vulnerability

Showing 20 of 54 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2021-41349へのコメント

まだコメントはありません


コメントを残す