SB2021020931 - Multiple vulnerabilities in Microsoft Exchange Server
Published: February 9, 2021 Updated: February 25, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Cross-site request forgery (CVE-ID: CVE-2021-24085)
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insecure generation of CSRF tokens for office-addins installation within the HasValidCanary function inside of the Canary15 class. A remote user can trick the victim to visit a specially crafted web page and escalate privileges on the server.
2) Spoofing attack (CVE-ID: CVE-2021-1730)
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of user-supplied data in the Exchange Server Installer. A remote attacker can spoof page content.
Remediation
Install update from vendor's website.