CVE-2024-21410Active Exploitation(microsoft / exchange_server)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch microsoft exchange_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Microsoft Exchange Server Elevation of Privilege Vulnerability

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-03-07. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-287

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exchange_server

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
exchange_server

2 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-03: 2PoC Mentioned / Linked · 2026-05-03: 1Exploit Tool / Code · 2026-05-03: 1Active Exploitation · 2026-05-03: 2Patch / Workaround · 2026-05-03: 1Technical Details · 2026-05-03: 205-03
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-21410: Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. Status: ✅ Confirmed exploited in the wild Date added: 2024-02-15 Required action: Apply mitigations per vendor instructions or discontinue use of the…

    Post summary

    CVE-2024-21410 is a privilege‑escalation vulnerability in Microsoft Exchange Server that has been confirmed exploited in the wild, and users are urged to apply vendor mitigations or discontinue use.

    1000078
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://lyrie.ai/research/research/active-exploit-cve-2024-21410-exchange-server #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The article announces an active exploitation of CVE‑2024‑21410 against Microsoft Exchange Server, confirming PoC and exploit code availability, while no patch or mitigation is referenced.

    0000027
    152 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--

Explore more