EXPOSURES › CVE-2024-21410
CVE-2024-21410
HIGH ⌖ ON CISA KEV · EXPLOITEDMicrosoft Exchange Server is actively exploited via CVE-2024-21410, enabling privilege escalation and ransomware entry.
This vulnerability allows unauthorized privilege escalation in Exchange Server, creating a high-risk exposure for DIB organizations relying on Microsoft Exchange for sensitive data. The CVE is actively exploited in the wild, indicating immediate remediation is required to prevent unauthorized access and potential data breaches.
Shame score — Active exploitation of a known privilege escalation vulnerability in a widely deployed product indicates systemic security failures and negligence in patch management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |