CVE-2024-21410

Microsoft Exchange Server Elevation of Privilege Vulnerability

Microsoft Exchange Server Elevation of Privilege Vulnerability


We have discovered 3,177 live websites that are affected by CVE-2024-21410.

Run a Free Instant Scan




Affected Software

Product  Microsoft Exchange Server
Category Web Mail
Vulnerable Domains3,177 live websites (35% of Microsoft Exchange Server install base)
Vulnerable Versions
  • from 15.1 through 15.1.2507.37
Vulnerable Versions Count22 versions ( 22% of all versions)


Common Weakness Enumeration

CWE-287 Improper Authentication



Details

  • Published - Feb 13, 2024
  • Updated - Oct 21, 2025

Website Distribution by Country

Number of websites using CVE-2024-21410
United States812 websites



Germany252 websites
Russia152 websites
GB128 websites
Canada106 websites
France100 websites
Italy100 websites
Czech Republic94 websites
Austria77 websites
Taiwan72 websites

Website Distribution by TLD

Number of websites using CVE-2024-21410
.com870 websites
.org271 websites
.de206 websites
.ru127 websites
.net108 websites
.cz88 websites
.fr76 websites
.it68 websites
.edu59 websites
.nl54 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-21410

Top websites that are affected by CVE-2024-21410. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**.de Germany**,***
***.***.tw Taiwan**,***
***.***.cn China***,***
*******.***.tw Taiwan***,***
********.ru Russia***,***
****.***.***.vn Vietnam***,***
*******.ru Russia***,***
****.***.tw Taiwan***,***
**********.pt Portugal***,***
***********.to Tonga***,***
See full domain list

FAQ

CVE-2024-21410 is Improper Authentication in Microsoft Exchange Server
A total of 3,177 websites have been identified as vulnerable to CVE-2024-21410, based on global website indexing conducted by WebTechSurvey.
The Microsoft Exchange Server is affected by the CVE-2024-21410 vulnerability.
Microsoft Exchange Server versions up to 15.1.2507.37 are vulnerable to CVE-2024-21410.
CVE-2024-21410 is resolved in version 15.1.2507.37 of Microsoft Exchange Server.