S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-34473 Scanner

CVE-2021-34473 scanner - Remote Code Execution (RCE) vulnerability in Microsoft Exchange Server 2013, Microsoft Exchange Server 2019, Microsoft Exchange Server 2016

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
6
Times Used
by S4E users
4
Assets Scanned
domains & IPs
4
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-34473
9.1
CVSScritical
Exploitable remotely over the internet · no authentication required.
Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Microsoft Exchange Server 2013 Cumulative Update 23by Microsoft
AFFECTED< 15.00.1497.015SAFE ✓≥ 15.00.1497.015
Microsoft Exchange Server 2016 Cumulative Update 19by Microsoft
AFFECTED< 15.01.2176.012SAFE ✓≥ 15.01.2176.012
Microsoft Exchange Server 2016 Cumulative Update 20by Microsoft
AFFECTED< 15.01.2242.008SAFE ✓≥ 15.01.2242.008
Microsoft Exchange Server 2019 Cumulative Update 8by Microsoft
AFFECTED< 15.02.0792.013SAFE ✓≥ 15.02.0792.013
Updated Aug 19, 2026View on NVD →
Detail

Microsoft Exchange Server products are designed for organizations that require secure and efficient messaging. Microsoft Exchange Server 2013, Microsoft Exchange Server 2019, and Microsoft Exchange Server 2016 are widely used worldwide. These products serve as a communication hub that enables users to send and receive emails, manage calendars, contacts, and tasks, among other features. The Microsoft Exchange Server is an on-premises email server that is used by many organizations worldwide.

CVE-2021-34473 is a remote code execution vulnerability detected in Microsoft Exchange Server. This vulnerability is similar to the previous exploits that targeted the Exchange Server earlier this year, including CVE-2021-31196 and CVE-2021-31206. The vulnerability is caused by the Exchange Security Feature Bypass that allows an attacker to execute arbitrary code on the server with SYSTEM privileges. The attacker could take complete control over the Exchange Server, read or modify sensitive data, and install malware.

This vulnerability can lead to severe consequences for organizations using Microsoft Exchange Server products. Attackers can execute harmful codes, install malware, steal sensitive data, and spread the malware across the network of the affected organization. The damage caused by such attacks can be costly, involving not only financial losses but also reputational damage and loss of productivity for the organization.

s4e.io is a reliable platform that provides organizations with professional security monitoring services. The platform allows users to identify and track vulnerabilities and threats in their digital assets, including applications, websites, and servers. With s4e.io, users can easily and quickly learn about the CVE-2021-34473 vulnerability and other potential attacks that may affect their systems. By leveraging the pro features of this platform, organizations can enhance their security posture and avoid becoming victims of cyberattacks.

 

REFERENCES

Solution Advice

To prevent this vulnerability, Microsoft released a security update on July 13, 2021. Organizations using the affected versions of Microsoft Exchange Server are urged to update their systems as soon as possible to prevent potential attacks. Below are some other measures that can be taken to protect against this vulnerability:

  • Install the latest security updates for the affected versions of Microsoft Exchange Server.
  • Block incoming connections to port 443 to the Exchange Server, except for those coming from trusted sources.
  • Enable Network Intrusion Prevention System (NIPS) and Network Intrusion Detection System (NIDS) to monitor and detect any traffic exploiting this vulnerability.
  • Deploy protective software such as an antivirus and antimalware solution to monitor and protect the system from malicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.