CVE-2024-21410: Microsoft Exchange Server Privilege Escalation Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-02-15. EPSS: 12.6% chance of exploitation in the next 30 days.

Microsoft Exchange Server Elevation of Privilege Vulnerability

Affected products

  • Microsoft Exchange Server: version 2016 only; version 2019 only

Published 2024-02-13. Last modified 2026-06-17.