CVE-2021-24085
published 2021-02-25CVE-2021-24085: Microsoft Exchange Server Spoofing Vulnerability Microsoft Exchange Server Spoofing Vulnerability
medium5.5CVSS 3.1
AVNACLPRLUIRSUCLILAL
EPSS
4.63%
90.7th percentile
Microsoft Exchange Server Spoofing Vulnerability
Microsoft Exchange Server Spoofing Vulnerability
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_exchange_server_2016_cumulative_update_18 | >= 15.01.0 < publication | publication |
| microsoft | microsoft_exchange_server_2016_cumulative_update_19 | >= 15.01.0 < publication | publication |
| microsoft | microsoft_exchange_server_2019_cumulative_update_7 | >= 15.02.0 < publication | publication |
| microsoft | microsoft_exchange_server_2019_cumulative_update_8 | >= 15.02.0 < publication | publication |
| msrc | microsoft_exchange_server_2010_service_pack_3 | — | — |
| msrc | microsoft_exchange_server_2013_cumulative_update_21 | — | — |
| msrc | microsoft_exchange_server_2013_cumulative_update_22 | — | — |
| msrc | microsoft_exchange_server_2013_cumulative_update_23 | — | — |
| msrc | microsoft_exchange_server_2013_service_pack_1 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_10 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_11 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_12 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_13 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_14 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_15 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_16 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_17 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_18 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_19 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_8 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_9 | — | — |
| msrc | microsoft_exchange_server_2019 | — | — |
| msrc | microsoft_exchange_server_2019_cumulative_update_1 | — | — |
| msrc | microsoft_exchange_server_2019_cumulative_update_2 | — | — |
| msrc | microsoft_exchange_server_2019_cumulative_update_3 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
cvelistv56.5MEDIUM
vendor_msrc9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Exchange Server Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 7.8
CVE-2021-26857 [CRITICAL] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
FAQ: Is this vulnerability being used in an active attack?
Yes. The vulnerability described in this CVE is one of four vulnerabilities that are being exploited in an active attack. The security updates address this attack. More information can be found here: https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server.
What is the target for this attack?
The initial attack in this attack chain targets an Exchange On-prem server that is able to receive untrusted connections from an external source. In addition, the Exchange server would need to be running Microsoft Exchange Server 2013, 2016, or 2019.
Where can I get more information about how to protect myself from the vulnerabilities?
Pleas
Microsoft
Microsoft Exchange Server Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 9.1
CVE-2021-26855 [CRITICAL] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
FAQ: Is this vulnerability being used in an active attack?
Yes. The vulnerability described in this CVE is one of four vulnerabilities that are being exploited in an active attack. The security updates address this attack. More information can be found here: https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server.
What is the target for this attack?
The initial attack in this attack chain targets an Exchange On-prem server that is able to receive untrusted connections from an external source. In addition, the Exchange server would need to be running Microsoft Exchange Server 2013, 2016, or 2019.
Where can I get more information about how to protect myself from the vulnerabilities?
Pleas
Microsoft
Microsoft Exchange Server Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 7.8
CVE-2021-27065 [CRITICAL] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
FAQ: Is this vulnerability being used in an active attack?
Yes. The vulnerability described in this CVE is one of four vulnerabilities that are being exploited in an active attack. The security updates address this attack. More information can be found here: https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server.
What is the target for this attack?
The initial attack in this attack chain targets an Exchange On-prem server that is able to receive untrusted connections from an external source. In addition, the Exchange server would need to be running Microsoft Exchange Server 2013, 2016, or 2019.
Where can I get more information about how to protect myself from the vulnerabilities?
Pleas
Microsoft
Microsoft Exchange Server Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 7.8
CVE-2021-26858 [CRITICAL] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
FAQ: Is this vulnerability being used in an active attack?
Yes. The vulnerability described in this CVE is one of four vulnerabilities that are being exploited in an active attack. The security updates address this attack. More information can be found here: https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server.
What is the target for this attack?
The initial attack in this attack chain targets an Exchange On-prem server that is able to receive untrusted connections from an external source. In addition, the Exchange server would need to be running Microsoft Exchange Server 2013, 2016, or 2019.
Where can I get more information about how to protect myself from the vulnerabilities?
Pleas
Microsoft
Microsoft Exchange Server Spoofing Vulnerability
vendor_msrc·2021-02-09·CVSS 6.5
CVE-2021-24085 [MEDIUM] Microsoft Exchange Server Spoofing Vulnerability
Microsoft Exchange Server Spoofing Vulnerability
FAQ: What is the nature of the spoofing?
An authenticated attacker can leak a cert file which results in a CSRF token to be generated.
Microsoft Exchange Server: Microsoft Exchange Server
Microsoft: Microsoft
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://www.microsoft.com/download/details.aspx?familyid=1a27365b-3ef6-4755-a2de-9733c1107efc
Reference: https://support.microsoft.com/help/4602269
Reference: http://www.microsoft.com/download/details.aspx?familyid=7dd6bd46-9bf2-4b1b-a7ed-69221f8225a9
Reference: http://www.microsoft.com/download/details.aspx?familyid=543dff06-10b4-4c99-b8ab-17cecb
GHSA
GHSA-2rhv-qrh4-ppvg: Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-1730
ghsa_unreviewed·2022-05-24·CVSS 5.4
CVE-2021-24085 [MEDIUM] GHSA-2rhv-qrh4-ppvg: Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-1730
Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-1730.
GHSA
GHSA-mp5r-32pv-q987: Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-24085
ghsa_unreviewed·2022-05-24·CVSS 6.5
CVE-2021-1730 [MEDIUM] GHSA-mp5r-32pv-q987: Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-24085
Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-24085.
CVEList
Microsoft Exchange Server Spoofing Vulnerability
cvelistv5·2021-02-25·CVSS 6.5
CVE-2021-24085 [MEDIUM] Microsoft Exchange Server Spoofing Vulnerability
Microsoft Exchange Server Spoofing Vulnerability
Microsoft Exchange Server Spoofing Vulnerability
No detection rules found.
No public exploits indexed.
Talos
Quarterly Report: Incident Response trends from Spring 2021
blogs_talos·2021-06-10·CVSS 9.1
CVE-2021-26855 [CRITICAL] Quarterly Report: Incident Response trends from Spring 2021
## Quarterly Report: Incident Response trends from Spring 2021
By David Liebenberg and Caitlin Huey .
While the security community made a great effort to warn users of the exploitation of several Microsoft Exchange Server zero-day vulnerabilities , it was still the biggest threat Cisco Talos Incident Response (CTIR) saw this past quarter. These vulnerabilities, tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065, comprised around 35 percent of all incidents investigated.
This shows that when a vulnerability is recently disclosed, severe, and widespread, CTIR will often see a corresponding rise in engagements in which the vulnerabilities in question are involved. Thankfully, the majority of these incidents involved scanning and not post-compromise behavior, such
Talos
Quarterly Report: Incident Response trends from Spring 2021
blogs_talos·2021-06-10·CVSS 9.1
CVE-2021-26855 [CRITICAL] Quarterly Report: Incident Response trends from Spring 2021
By David Liebenberg and Caitlin Huey.
While the security community made a great effort to warn users of the exploitation of several Microsoft Exchange Server zero-day vulnerabilities, it was still the biggest threat Cisco Talos Incident Response (CTIR) saw this past quarter. These vulnerabilities, tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065, comprised around 35 percent of all incidents investigated.
This shows that when a vulnerability is recently disclosed, severe, and widespread, CTIR will often see a corresponding rise in engagements in which the vulnerabilities in question are involved. Thankfully, the majority of these incidents involved scanning and not post-compromise behavior, such as file encryption or evidence of exfiltration.
While CTIR’s focu
Talos
Hafnium Update: Continued Microsoft Exchange Server Exploitation
blogs_talos·2021-03-10
Hafnium Update: Continued Microsoft Exchange Server Exploitation
Update 3/11: The following OSQuery detects active commands being run through webshells observed used by actors on compromised Exchange servers. While systems may have been patched to defend against Hafnium and others, threat actors may have leveraged these vulnerabilities to establish additional persistence in victim networks. A thorough forensic investigation will be required to determine additional compromises.
It's been a week since Microsoft first disclosed several zero-day vulnerabilities in Exchange Server — and the scope has only grown since then. In its disclosure, Microsoft stated that a new threat actor known as Hafnium was exploiting these vulnerabilities to steal emails.
Since Microsoft's initial disclosure, Cisco Talos has seen shifts in the tactics, techniques, and procedur
Talos
Hafnium Update: Continued Microsoft Exchange Server Exploitation
blogs_talos·2021-03-10
Hafnium Update: Continued Microsoft Exchange Server Exploitation
## Hafnium Update: Continued Microsoft Exchange Server Exploitation
Update 3/11 : The following OSQuery detects active commands being run through webshells observed used by actors on compromised Exchange servers. While systems may have been patched to defend against Hafnium and others, threat actors may have leveraged these vulnerabilities to establish additional persistence in victim networks. A thorough forensic investigation will be required to determine additional compromises.
It's been a week since Microsoft first disclosed several zero-day vulnerabilities in Exchange Server — and the scope has only grown since then. In its disclosure, Microsoft stated that a new threat actor known as Hafnium was exploiting these vulnerabilities to steal emails.
Since Microsoft's initial disclosure
Talos
Threat Advisory: HAFNIUM and Microsoft Exchange zero-day
blogs_talos·2021-03-04·CVSS 9.1
CVE-2021-26855 [CRITICAL] Threat Advisory: HAFNIUM and Microsoft Exchange zero-day
Microsoft released patches for four vulnerabilities in Exchange Server on March 2, disclosing that these vulnerabilities were being exploited by a previously unknown threat actor, referred to as HAFNIUM.
The vulnerabilities in question — CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065 — affect Microsoft Exchange Server 2019, 2016, 2013 and the out-of-support Microsoft Exchange Server 2010. The patches for these vulnerabilities should be applied as soon as possible. Microsoft Exchange Online is not affected.
Patches for an additional three vulnerabilities in the same software have also been released: CVE-2021-26412, CVE-2021-26854 and CVE-2021-27078. It is believed that these vulnerabilities have not yet been exploited in the wild.
## Threat activity details
The threat
Talos
Threat Advisory: HAFNIUM and Microsoft Exchange zero-day
blogs_talos·2021-03-04·CVSS 9.1
CVE-2021-26855 [CRITICAL] Threat Advisory: HAFNIUM and Microsoft Exchange zero-day
## Threat Advisory: HAFNIUM and Microsoft Exchange zero-day
Microsoft released patches for four vulnerabilities in Exchange Server on March 2, disclosing that these vulnerabilities were being exploited by a previously unknown threat actor, referred to as HAFNIUM .
The vulnerabilities in question — CVE-2021-26855 , CVE-2021-26857 , CVE-2021-26858 and CVE-2021-27065 — affect Microsoft Exchange Server 2019, 2016, 2013 and the out-of-support Microsoft Exchange Server 2010. The patches for these vulnerabilities should be applied as soon as possible. Microsoft Exchange Online is not affected.
Patches for an additional three vulnerabilities in the same software have also been released: CVE-2021-26412 , CVE-2021-26854 and CVE-2021-27078 . It is believed that these vulnerabilities have not yet b
Greynoiseio
NoiseLetter February 2026
blogs_greynoiseio
NoiseLetter February 2026
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Crowdstrike
Falcon Complete Stops Microsoft Exchange Server Zero-Day Exploits
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Falcon Complete Stops Microsoft Exchange Server Zero-Day Exploits
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2021-02-25
Published