CVE-2021-31980: Microsoft Intune Management Extension Remote Code Execution Vulnerability

Overview

Severity
High (CVSS 8.1)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Remote Code Execution
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2021-Jun
Released
2021-06-08
EPSS Score
5.07% (percentile: 89.8%)

FAQ

What should I do to protect myself from this vulnerability? No action is required. As soon as the client connects to the service, it automatically receives a message to upgrade.

Affected Products (1)

Apps

  • Intune management extension

Acknowledgments

Aapo Oksman of <a href="https://nixu.com">Nixu Cybersecurity</a>

Revision History

  • 2021-06-08: Information published.