CVE-2021-33766
Microsoft Exchange Server Information Disclosure
CVSS
7.3
High
EPSS
98.1%
p100
KEV
YES
Jan 18, 2022
Exploit Today
80
0-100
Published: Jul 14, 2021 · Last modified: Aug 10, 2026
97.5%EPSS · 30 days98.2%
2026-08-022026-08-30
Product
Microsoft / Exchange Server
Vulnerability
Microsoft Exchange Server Information Disclosure
Added to KEV
Jan 18, 2022
Remediate by
Feb 1, 2022
Known ransomware use
No
Summary description
Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.
Required action
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2021-33766
Microsoft Exchange Server Information Disclosure Vulnerability
- msrc.microsoft.comhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-33766
- portal.msrc.microsoft.comhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-33766
- www.zerodayinitiative.comhttps://www.zerodayinitiative.com/advisories/ZDI-21-798/
- www.cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-33766
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-215298.8 HIG99.1%
KEV—80Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability11dCVE-2022-410808.8 HIG99.5%
KEV—80Microsoft Exchange Server Privilege Escalation Vulnerability21dCVE-2021-345239.0 CRI100.0%
KEV—80Microsoft Exchange Server Privilege Escalation Vulnerability20dCVE-2021-344739.1 CRI100.0%
KEV—80Microsoft Exchange Server Remote Code Execution Vulnerability20dCVE-2021-311967.2 HIG98.9%
KEV—80Microsoft Exchange Server Information Disclosure Vulnerability20dCVE-2021-270657.8 HIG100.0%
KEV—80Microsoft Exchange Server Remote Code Execution Vulnerability11d