Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryinternet-facing-service-vulnerabilityendpoint-software-vulnerability

Microsoft Exchange Server Elevation of Privilege Flaws Prompt Repeated Patching

Updated 29d agoFirst seen May 25, 20265 sources

Microsoft has disclosed multiple elevation of privilege vulnerabilities affecting Microsoft Exchange Server, including CVE-2021-34470, CVE-2021-41348, CVE-2022-41123, and CVE-2025-64666, indicating a recurring security issue in the on-premises mail platform across several release cycles. The advisories show Exchange continued to receive fixes for privilege-escalation weaknesses over multiple years, with Microsoft publishing separate Security Update Guide entries as new flaws were identified.

Among the listed issues, Microsoft provided the most detail for CVE-2021-34470, rating it Important with a CVSS 3.0 score of 8.0 and describing it as requiring access from a logically adjacent network. Microsoft said the flaw required a schema change and was fixed for Exchange Server 2019 and Exchange Server 2016 in cumulative updates released on June 29, 2021; at initial publication, the company said it was not publicly disclosed, not exploited, and less likely to be exploited. A separate Microsoft advisory in the same reference set, CVE-2026-26128, affects the Windows SMB Server rather than Exchange and also involves elevation of privilege.

Share:
Microsoft Exchange Server Elevation of Privilege Flaws Prompt Repeated Patching
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Mar 10, 20264mo ago

Microsoft publishes CVE-2026-26128 advisory for Windows SMB Server

Microsoft published a Security Update Guide entry for CVE-2026-26128, identified as a Windows SMB Server elevation of privilege vulnerability. No additional synopsis details were provided in the reference.

Dec 9, 20257mo ago

Microsoft publishes CVE-2025-64666 advisory for Exchange Server

Microsoft published a Security Update Guide entry for CVE-2025-64666, identified as a Microsoft Exchange Server elevation of privilege vulnerability. No additional synopsis details were provided in the reference.

Nov 8, 20224y ago

Microsoft publishes CVE-2022-41123 advisory for Exchange Server

Microsoft published a Security Update Guide entry for CVE-2022-41123, identified as a Microsoft Exchange Server elevation of privilege vulnerability. No additional synopsis details were provided in the reference.

Oct 12, 20215y ago

Microsoft publishes CVE-2021-41348 advisory for Exchange Server

Microsoft published a Security Update Guide entry for CVE-2021-41348, identified as a Microsoft Exchange Server elevation of privilege vulnerability. No additional synopsis details were provided in the reference.

Jul 13, 20215y ago

Microsoft discloses CVE-2021-34470 for Exchange Server

Microsoft published advisory details for CVE-2021-34470, an Important Microsoft Exchange Server elevation of privilege vulnerability with a CVSS 3.0 score of 8.0. At disclosure, Microsoft assessed it as not publicly disclosed, not exploited, and less likely to be exploited.

Jun 29, 20215y ago

Microsoft releases Exchange cumulative updates fixing CVE-2021-34470

Microsoft fixed the Microsoft Exchange Server elevation of privilege vulnerability CVE-2021-34470 in cumulative updates for Exchange Server 2019 and Exchange Server 2016. The fix required a schema change and was released as part of the June 29, 2021 cumulative updates.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Microsoft Exchange Server Elevation of Privilege Flaws Prompt Repeated Patching | Mallory