CVE Radar

CVE Radar Logo
CVERadar

Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For Free

CVE-2024-21410

Critical Severity|Microsoft
89
SVRS
9.8
CVSSv3
0.12661
EPSS
TAGS
In The WildExploit AvaliableCISA KEV
VECTOR STRING
CVSS:3.1AV:NAC:LPR:NUI:NS:UC:HI:HA:H
PUBLICATION DATE2024-02-13
LAST MODIFIED2025-10-21

Deep CVE Analysis in Progress

The system is currently conducting an in-depth analysis of the selected CVE. This includes advanced correlation, vulnerability classification, and cross-referencing with real-time threat intelligence sources. Once the analysis is complete, the page will automatically update with enriched vulnerability data and actionable insights.

Security Intelligence Brief

1. What is this vulnerability and why does it matter?
This is a critical Elevation of Privilege vulnerability affecting Microsoft Exchange Server, identified as CVE-2024-21410. It matters significantly because an attacker who successfully exploits this vulnerability could elevate their privileges on the Exchange server, potentially gaining control over sensitive data, user accounts, and the server itself. The existence of active exploits further escalates its importance, requiring immediate attention.
2. What are the CVSS score, severity level, and disclosure details?
The CVSS score for CVE-2024-21410 is 9.8, categorizing it as a Critical severity vulnerability. It was initially published on 2024-02-13 18:02:48 and last modified on 2025-10-21 23:05:24. Crucially, active exploits have been published, indicating that the vulnerability is actively being targeted in the wild.
3. Which products, vendors, systems, and versions are affected?
This vulnerability specifically affects Microsoft Exchange Server. The provided CVE data does not specify particular versions of Microsoft Exchange Server that are impacted, but it is tied to the Exchange Server product line.
4. What is the technical root cause and attack vector?
The technical root cause is identified as CWE-287, which corresponds to Improper Authentication. This suggests that the vulnerability stems from flaws in how the Exchange Server authenticates or verifies user identities and permissions, allowing an attacker to bypass or subvert these checks to gain elevated privileges. The precise attack vector, while not fully detailed in the provided data, is an Elevation of Privilege, which typically involves a sophisticated method of exploiting authentication or authorization mechanisms within the server to gain higher access rights.
5. How can this vulnerability be exploited?
CVE-2024-21410 is an Elevation of Privilege vulnerability. While the exact method of exploitation is not detailed in the provided data, the presence of active exploits indicates that specific techniques to leverage improper authentication (CWE-287) are known and being used by threat actors to gain higher privileges on affected Microsoft Exchange Servers.
9. Which threat actors are known to exploit this vulnerability?
While the CVE data states that active exploits have been published, specific threat actors known to exploit this vulnerability are not mentioned.
10. What public intelligence references and advisories exist?
The primary public intelligence reference is CVE-2024-21410 itself. The existence of active exploits, as indicated in the CVE data, serves as a critical advisory warning about the immediate threat this vulnerability poses. The vulnerability's publication date is 2024-02-13 and it was last modified on 2025-10-21.
11. What is the risk assessment and urgency level?
The risk assessment for CVE-2024-21410 is Critical. This is primarily driven by its CVSS score of 9.8, indicating maximum severity, and its classification as an Elevation of Privilege vulnerability. The urgency level is Immediate, as the CVE data explicitly states that active exploits have been published. This means the vulnerability is being actively targeted, making affected systems highly susceptible to compromise and requiring prompt mitigation.

No IOCs found for this CVE

TitleSoftware LinkDate
JohnBordon/CVE-2024-21410-pochttps://github.com/JohnBordon/CVE-2024-21410-poc2024-04-08
FreakyM0ndy/CVE-2024-21410-pochttps://github.com/FreakyM0ndy/CVE-2024-21410-poc2024-03-01
Microsoft Exchange Server Privilege Escalation Vulnerabilityhttps://www.cisa.gov/search?g=CVE-2024-214102024-02-15
Ostorlab/KEVhttps://github.com/Ostorlab/KEV2022-04-19
nomi-sec/PoC-in-GitHubhttps://github.com/nomi-sec/PoC-in-GitHub2019-12-08
SOCRadar Logo

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence

Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.

CREATE FREE ACCOUNT
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs
Mitigating NTLM Relay Attacks by Default
2025-12-01
Mitigating NTLM Relay Attacks by Default | Introduction In February 2024, we released an update to Exchange Server which contained a security improvement referenced by CVE-2024-21410 that enabled Extended Protection for Authentication (EPA) by default for new and existing installs of Exchange 2019. While we’re currently unaware of any active threat campaigns involving NTLM relaying attacks against Exchange, we have observed threat actors exploiting this vector in the past.
microsoft.comrssforumnews
avatar
Lyrie.ai@lyrie_ai
2026-05-03
CVE-2024-21410: Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. Status: ✅ Confirmed exploited in the wild Date added: 2024-02-15 Required action: Apply mitigations per vendor instructions or discontinue use of the…
avatar
Joe Stocker@ITguySoCal
2025-10-31
Last year's CVE-2024-21410 revealed 163,244 Microsoft Exchange servers exposed to the internet. As of right now, Shodan reports 206,510 (when excluding MSFT EXO). Only 18,665 in the United States. Who knows how many are actually honeypots run by researchers like @shotgunner101
Configuration 1
TypeVendorProduct
AppMicrosoftexchange_server
ReferenceLink
MICROSOFT EXCHANGE SERVER ELEVATION OF PRIVILEGE VULNERABILITYhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21410
AF854A3A-2127-422B-91AE-364DA2661108https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21410
[email protected]https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21410
[email protected]https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21410
MICROSOFT EXCHANGE SERVER ELEVATION OF PRIVILEGE VULNERABILITYhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21410
CWE IDCWE NameDescription
CWE-287Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.