cbcvebase.
CVE-2021-31196
published 2021-07-14

CVE-2021-31196: Microsoft Exchange Server Remote Code Execution Vulnerability

PriorityP182high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2024-09-11
Exploited in the wild
EPSS
46.38%
98.7th percentile
Microsoft Exchange Server Remote Code Execution Vulnerability

Affected

13 ranges
VendorProductVersion rangeFixed in
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftmicrosoft_exchange_server_2013_cumulative_update_23>= 15.00.0 < 15.00.1497.02315.00.1497.023
microsoftmicrosoft_exchange_server_2016_cumulative_update_20>= 15.01.0 < 15.01.2242.01215.01.2242.012
microsoftmicrosoft_exchange_server_2016_cumulative_update_21>= 15.01.0 < 15.01.2308.01415.01.2308.014
microsoftmicrosoft_exchange_server_2019_cumulative_update_10>= 15.02.0 < 15.02.0922.01315.02.0922.013
microsoftmicrosoft_exchange_server_2019_cumulative_update_9>= 15.02.0 < 15.02.0858.01515.02.0858.015
msrcmicrosoft_exchange_server_2013_cumulative_update_23
msrcmicrosoft_exchange_server_2016_cumulative_update_20
msrcmicrosoft_exchange_server_2016_cumulative_update_21
msrcmicrosoft_exchange_server_2019_cumulative_update_10
msrcmicrosoft_exchange_server_2019_cumulative_update_9

Detection & IOCsextracted from sources · hover to see the quote

url/autodiscover/[email protected]/owa/?&Email=autodiscover/autodiscover.json%[email protected]
url/autodiscover/[email protected]/mapi/nspi/?&Email=autodiscover/autodiscover.json%[email protected]
otherMicrosoft.Exchange.Clients.Owa2.Server.Core.OwaADUserNotFoundException
otherExchange MAPI/HTTP Connectivity Endpoint
  • Detect exploitation attempts by matching HTTP GET requests to the autodiscover path-confusion SSRF pattern used in ProxyShell/ProxyOracle; look for the '@' character in the autodiscover.json URL path combined with an Email parameter containing an encoded '?' (%3F).
  • A response body containing 'Microsoft.Exchange.Clients.Owa2.Server.Core.OwaADUserNotFoundException' or 'Exchange MAPI/HTTP Connectivity Endpoint' confirms a vulnerable Exchange endpoint is responding to the SSRF probe.
  • Shodan fingerprinting: Exchange servers exposed to this CVE can be identified via favicon hash 1768726119 or the Shodan tag vuln:cve-2021-26855 (ProxyLogon-related exposure).
  • FOFA fingerprinting: Use icon_hash=1768726119 or title="outlook" to identify potentially vulnerable Exchange servers.
  • ·The Nuclei template provided targets CVE-2021-34473 (ProxyShell RCE), not CVE-2021-31196 directly. The SSRF probe paths and response matchers are associated with the ProxyShell attack chain; CVE-2021-31196 is an information disclosure vulnerability that can enable RCE. Detections based on this template may conflate the two CVEs.
  • ·CISA classifies CVE-2021-31196 as an information disclosure vulnerability that 'allows for remote code execution', indicating it is a stepping-stone rather than a standalone RCE; detection should account for chained exploitation scenarios.

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vulncheck7.2HIGH
cisa7.2HIGH
vendor_msrc7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.