Microsoft published security advisories for two information disclosure vulnerabilities affecting Microsoft Exchange Server and Microsoft Message Queuing (MSMQ), tracked as CVE-2021-33766 and CVE-2021-43236. The flaws were documented through the Microsoft Security Response Center as part of the company’s Security Update Guide, indicating that supported deployments of both enterprise messaging technologies required vendor-issued updates.
The disclosures highlight continued security risk in core Microsoft communication services used widely in corporate environments. Organizations running Exchange Server or MSMQ were advised to review the relevant advisories, determine exposure to the affected components, and apply Microsoft’s security updates to reduce the risk of unauthorized access to sensitive information.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft published Security Update Guide information for CVE-2021-43236, an information disclosure vulnerability affecting Microsoft Message Queuing.
Microsoft added CVE-2021-33766, an information disclosure vulnerability affecting Microsoft Exchange Server, to its Security Update Guide.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
portal.msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.