CVE-2021-31196
published 2021-07-14CVE-2021-31196: Microsoft Exchange Server Remote Code Execution Vulnerability
PriorityP182high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2024-09-11
Exploited in the wild
EPSS
46.38%
98.7th percentile
Microsoft Exchange Server Remote Code Execution Vulnerability
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | microsoft_exchange_server_2013_cumulative_update_23 | >= 15.00.0 < 15.00.1497.023 | 15.00.1497.023 |
| microsoft | microsoft_exchange_server_2016_cumulative_update_20 | >= 15.01.0 < 15.01.2242.012 | 15.01.2242.012 |
| microsoft | microsoft_exchange_server_2016_cumulative_update_21 | >= 15.01.0 < 15.01.2308.014 | 15.01.2308.014 |
| microsoft | microsoft_exchange_server_2019_cumulative_update_10 | >= 15.02.0 < 15.02.0922.013 | 15.02.0922.013 |
| microsoft | microsoft_exchange_server_2019_cumulative_update_9 | >= 15.02.0 < 15.02.0858.015 | 15.02.0858.015 |
| msrc | microsoft_exchange_server_2013_cumulative_update_23 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_20 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_21 | — | — |
| msrc | microsoft_exchange_server_2019_cumulative_update_10 | — | — |
| msrc | microsoft_exchange_server_2019_cumulative_update_9 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
url/autodiscover/[email protected]/owa/?&Email=autodiscover/autodiscover.json%[email protected]
url/autodiscover/[email protected]/mapi/nspi/?&Email=autodiscover/autodiscover.json%[email protected]
otherMicrosoft.Exchange.Clients.Owa2.Server.Core.OwaADUserNotFoundException
otherExchange MAPI/HTTP Connectivity Endpoint
- →Detect exploitation attempts by matching HTTP GET requests to the autodiscover path-confusion SSRF pattern used in ProxyShell/ProxyOracle; look for the '@' character in the autodiscover.json URL path combined with an Email parameter containing an encoded '?' (%3F).
- →A response body containing 'Microsoft.Exchange.Clients.Owa2.Server.Core.OwaADUserNotFoundException' or 'Exchange MAPI/HTTP Connectivity Endpoint' confirms a vulnerable Exchange endpoint is responding to the SSRF probe.
- →Shodan fingerprinting: Exchange servers exposed to this CVE can be identified via favicon hash 1768726119 or the Shodan tag vuln:cve-2021-26855 (ProxyLogon-related exposure).
- →FOFA fingerprinting: Use icon_hash=1768726119 or title="outlook" to identify potentially vulnerable Exchange servers.
- ·The Nuclei template provided targets CVE-2021-34473 (ProxyShell RCE), not CVE-2021-31196 directly. The SSRF probe paths and response matchers are associated with the ProxyShell attack chain; CVE-2021-31196 is an information disclosure vulnerability that can enable RCE. Detections based on this template may conflate the two CVEs.
- ·CISA classifies CVE-2021-31196 as an information disclosure vulnerability that 'allows for remote code execution', indicating it is a stepping-stone rather than a standalone RCE; detection should account for chained exploitation scenarios. ↗
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vulncheck7.2HIGH
cisa7.2HIGH
vendor_msrc7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Exchange Server Information Disclosure Vulnerability
cisa·2024-08-21·CVSS 7.2
CVE-2021-31196 [HIGH] Microsoft Exchange Server Information Disclosure Vulnerability
Vulnerability: Microsoft Exchange Server Information Disclosure Vulnerability
Affected: Microsoft Exchange Server
Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-31196; https://nvd.nist.gov/vuln/detail/CVE-2021-31196
Remediation Due Date: 2024-09-11
Microsoft
Microsoft Exchange Server Remote Code Execution Vulnerability
vendor_msrc·2021-07-13·CVSS 7.2
CVE-2021-31196 [HIGH] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server: Microsoft Exchange Server
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: http://www.microsoft.com/download/details.aspx?familyid=a78de9ec-af4e-4e31-be7d-17db9fc335db
Reference: https://support.microsoft.com/help/5004780
Reference: http://www.microsoft.com/download/details.aspx?familyid=61d75c2f-8b98-4971-b22c-ebd114772d3d
Reference: https://support.microsoft.com/help/5004779
Reference: http://www.microsoft.com/download/details.aspx?familyid=cae731a5-0d00-4f76-b2c6-84bd511e529f
Reference: https://support.microsoft.com/help/50
GHSA
GHSA-5jv9-cff9-2j3m: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31206, CVE-2021-34473
ghsa_unreviewed·2022-05-24·CVSS 7.6
CVE-2021-31196 [HIGH] GHSA-5jv9-cff9-2j3m: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31206, CVE-2021-34473
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31206, CVE-2021-34473.
GHSA
GHSA-636v-jm8j-6hx7: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31196, CVE-2021-34473
ghsa_unreviewed·2022-05-24·CVSS 7.2
CVE-2021-31206 [HIGH] GHSA-636v-jm8j-6hx7: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31196, CVE-2021-34473
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31196, CVE-2021-34473.
GHSA
GHSA-fgq9-p33g-xcfc: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31196, CVE-2021-31206
ghsa_unreviewed·2022-05-24·CVSS 7.2
CVE-2021-34473 [HIGH] CWE-918 GHSA-fgq9-p33g-xcfc: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31196, CVE-2021-31206
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31196, CVE-2021-31206.
VulnCheck
Microsoft Exchange Server Information Disclosure Vulnerability
vulncheck·2021·CVSS 7.2
CVE-2021-31196 [HIGH] Microsoft Exchange Server Information Disclosure Vulnerability
Microsoft Exchange Server Information Disclosure Vulnerability
Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.
Affected: Microsoft Exchange Server
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://cisa.gov/news-events/cybersecurity-advisories/aa22-257a; https://www.hhs.gov/sites/default/files/iranian-threat-actors-and-healthcare.pdf; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2024-09-11
No detection rules found.
Nuclei
Exchange Server - Remote Code Execution
nuclei·CVSS 7.2
CVE-2021-34473 [HIGH] Exchange Server - Remote Code Execution
Exchange Server - Remote Code Execution
Microsoft Exchange Server is vulnerable to a remote code execution vulnerability. This CVE ID is unique from CVE-2021-31196, CVE-2021-31206.
Template:
id: CVE-2021-34473
info:
name: Exchange Server - Remote Code Execution
author: arcc,intx0x80,dwisiswant0,r3dg33k
severity: critical
description: |
Microsoft Exchange Server is vulnerable to a remote code execution vulnerability. This CVE ID is unique from CVE-2021-31196, CVE-2021-31206.
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected Exchange Server, potentially leading to a complete compromise of the system.
remediation: Apply Microsoft Exchange Server 2019 Cumulative Update 9 or upgrade to the latest version.
reference:
- h
Tenable
AA22-257A: Cybersecurity Agencies Issue Joint Advisory on Iranian Islamic Revolutionary Guard Corps-Affiliated Attacks
blogs_tenable·2022-09-15
AA22-257A: Cybersecurity Agencies Issue Joint Advisory on Iranian Islamic Revolutionary Guard Corps-Affiliated Attacks
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
IT threat evolution in Q3 2021. PC statistics
blogs_securelist·2021-11-26
IT threat evolution in Q3 2021. PC statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Ransomware programs
Quarterly trends and highlights
Attack on Kaseya and the REvil story
The arrival of BlackMatter: DarkSide restored?
Q3 closures
Exploitation of vulnerabilities and new attack methods
Number of new ransomware modifications
Number of users attacked by ransomware Trojans
Geography of ransomware attacks
Top 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by cybercriminals during cyberattacks
Quarter highlights
Statistics
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
Countries tha
Securelist
IT threat evolution in Q3 2021. PC statistics
blogs_securelist·2021-11-26
IT threat evolution in Q3 2021. PC statistics
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Number of users attacked by ransomware Trojans
- Geography of ransomware attacks
- Top 10 most common families of ransomware Trojans
- Miners
- Vulnerable applications used by cybercriminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution Q3 2021
- IT threat evolution in Q3 2021. PC statistics
- IT threat evolution in Q3 2021. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q3 2021:
- Kaspersky solutions blocked 1,098,968,315 attacks from online reso
Tenable
Microsoft’s July 2021 Patch Tuesday Includes 116 CVEs (CVE-2021-31979, CVE-2021-33771)
blogs_tenable·2021-07-13·CVSS 7.8
[HIGH] Microsoft’s July 2021 Patch Tuesday Includes 116 CVEs (CVE-2021-31979, CVE-2021-33771)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Crowdstrike
July 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] July 2021 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Crowdstrike
July 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] July 2021 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2021-07-14
Published
2024-08-21
Added to CISA KEV
Exploited in the wild