Home / Vulnerabilities / CVE-2021-33766
HIGH SEVERITY
CVE-2021-33766 Microsoft · Exchange Server

Microsoft Exchange Server Information Disclosure

Technical Severity

CVSS v3.1 Metrics

HIGH
7.3 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C
Exploitation Likelihood

EPSS Prediction

93.48 %
Predictive Probability
Percentile Rank
99.8 th

Documented as more likely to be exploited than 99.8% of known CVEs.

Detection Date

Jan 18, 2022

Remediation Due

Feb 01, 2022

CISA Catalog Active

Threat Analysis

Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.

Remediation Directive

Apply updates per vendor instructions.

External Intelligence