January 18, 2022 · Applied Cybernetics Group
CVE-2021-33766 — Microsoft Exchange Server
Microsoft Exchange Server Information Disclosure
- Added to KEV
2022-01-18- Federal due date
2022-02-01- Vendor
- Microsoft
- Product
- Exchange Server
- EPSS
- 99.9th percentile (score 0.938, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2021-33766
CISA short description
Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.
Required action
Apply updates per vendor instructions.