CVE-2021-31206
published 2021-07-14CVE-2021-31206: Microsoft Exchange Server Remote Code Execution Vulnerability
PriorityP181high8CVSS 3.1
AVAACLPRNUIRSUCHIHAH
ITWEXPLOITVulnCheck KEVRansomware
Exploited in the wild
EPSS
9.79%
95.0th percentile
Microsoft Exchange Server Remote Code Execution Vulnerability
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | microsoft_exchange_server_2013_cumulative_update_23 | >= 15.00.0 < 15.00.1497.023 | 15.00.1497.023 |
| microsoft | microsoft_exchange_server_2016_cumulative_update_20 | >= 15.01.0 < 15.01.2242.012 | 15.01.2242.012 |
| microsoft | microsoft_exchange_server_2016_cumulative_update_21 | >= 15.01.0 < 15.01.2308.014 | 15.01.2308.014 |
| microsoft | microsoft_exchange_server_2019_cumulative_update_10 | >= 15.02.0 < 15.02.0922.013 | 15.02.0922.013 |
| microsoft | microsoft_exchange_server_2019_cumulative_update_9 | >= 15.02.0 < 15.02.0858.015 | 15.02.0858.015 |
| msrc | microsoft_exchange_server_2013_cumulative_update_23 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_20 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_21 | — | — |
| msrc | microsoft_exchange_server_2019_cumulative_update_10 | — | — |
| msrc | microsoft_exchange_server_2019_cumulative_update_9 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
url{{BaseURL}}/autodiscover/[email protected]/owa/?&Email=autodiscover/autodiscover.json%[email protected]↗
url{{BaseURL}}/autodiscover/[email protected]/mapi/nspi/?&Email=autodiscover/autodiscover.json%[email protected]↗
- →Probe Exchange /autodiscover/autodiscover.json endpoint with @-prefixed email parameter to detect ProxyShell SSRF (CVE-2021-31206 exploit chain). Response body containing 'OwaADUserNotFoundException' or 'Exchange MAPI/HTTP Connectivity Endpoint' indicates a vulnerable/exploited server. ↗
- →CVE-2021-31206 is part of the ProxyShell exploit chain (alongside CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) used by AvosLocker for initial access to Microsoft Exchange; monitor Exchange IIS logs for autodiscover endpoint abuse with @-prefixed parameters. ↗
- ·The Nuclei template probe paths use '{{BaseURL}}' as a placeholder; substitute with the actual Exchange server base URL when operationalizing detection. ↗
- ·The Qualys IOC report truncates the Windows SHA-256 hash in one instance; the full hash C0A42741EEF72991D9D0EE8B6C0531FC19151457A8B59BDCF7B6373D1FE56E02 is confirmed in the complete IOC section. ↗
- ·Microsoft's advisory states exploit status as 'Exploited: No' and 'Publicly Disclosed: No' at time of publication; however, threat actors (AvosLocker) have since weaponized this CVE as part of the ProxyShell chain in real-world attacks. ↗
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.9HIGHAV:A/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.6HIGH
vendor_msrc7.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5jv9-cff9-2j3m: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31206, CVE-2021-34473
ghsa_unreviewed·2022-05-24·CVSS 7.6
CVE-2021-31196 [HIGH] GHSA-5jv9-cff9-2j3m: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31206, CVE-2021-34473
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31206, CVE-2021-34473.
GHSA
GHSA-636v-jm8j-6hx7: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31196, CVE-2021-34473
ghsa_unreviewed·2022-05-24·CVSS 7.2
CVE-2021-31206 [HIGH] GHSA-636v-jm8j-6hx7: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31196, CVE-2021-34473
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31196, CVE-2021-34473.
GHSA
GHSA-fgq9-p33g-xcfc: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31196, CVE-2021-31206
ghsa_unreviewed·2022-05-24·CVSS 7.2
CVE-2021-34473 [HIGH] CWE-918 GHSA-fgq9-p33g-xcfc: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31196, CVE-2021-31206
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31196, CVE-2021-31206.
VulnCheck
Microsoft Exchange Server Remote Code Execution
vulncheck·2021·CVSS 7.6
CVE-2021-31206 [HIGH] Microsoft Exchange Server Remote Code Execution
Microsoft Exchange Server Remote Code Execution
Microsoft Exchange Server Remote Code Execution Vulnerability
Affected: Microsoft Exchange Server
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://blog.cyble.com/2022/01/17/avoslocker-ransomware-linux-version-targets-vmware-esxi-servers/; https://cybersecurityworks.com/howdymanage/uploads/file/RansomwareUpdate%20Report%202022%20Q1.pdf; https://static.tenable.com/marketing/whitepapers/Whitepaper-Ransomware_Ecosystem.pdf; https://cisa.gov/news-events/cybersecurity-advisories/aa22-257a; https://www.ivanti.com/resources/v/doc/pr-survey-report/ransomware-quarterly-inde
Microsoft
Microsoft Exchange Server Remote Code Execution Vulnerability
vendor_msrc·2021-07-13·CVSS 7.6
CVE-2021-31206 [HIGH] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
FAQ: Was this vulnerability found in the 2021 Pwn2Own contest?
Yes, this was one of the Exchange Server vulnerabilities found in the 2021 Pwn2Own contest.
Microsoft Exchange Server: Microsoft Exchange Server
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: http://www.microsoft.com/download/details.aspx?familyid=a78de9ec-af4e-4e31-be7d-17db9fc335db
Reference: https://support.microsoft.com/help/5004780
Reference: http://www.microsoft.com/download/details.aspx?familyid=61d75c2f-8b98-4971-b22c-ebd114772d3d
Reference: https://support.microsoft.com/help/500477
No detection rules found.
Nuclei
Exchange Server - Remote Code Execution
nuclei·CVSS 7.2
CVE-2021-34473 [HIGH] Exchange Server - Remote Code Execution
Exchange Server - Remote Code Execution
Microsoft Exchange Server is vulnerable to a remote code execution vulnerability. This CVE ID is unique from CVE-2021-31196, CVE-2021-31206.
Template:
id: CVE-2021-34473
info:
name: Exchange Server - Remote Code Execution
author: arcc,intx0x80,dwisiswant0,r3dg33k
severity: critical
description: |
Microsoft Exchange Server is vulnerable to a remote code execution vulnerability. This CVE ID is unique from CVE-2021-31196, CVE-2021-31206.
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected Exchange Server, potentially leading to a complete compromise of the system.
remediation: Apply Microsoft Exchange Server 2019 Cumulative Update 9 or upgrade to the latest version.
reference:
- h
Sentinelone
AvosLocker
blogs_sentinelone·2022-11-30
AvosLocker
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Tenable
AA22-257A: Cybersecurity Agencies Issue Joint Advisory on Iranian Islamic Revolutionary Guard Corps-Affiliated Attacks
blogs_tenable·2022-09-15
AA22-257A: Cybersecurity Agencies Issue Joint Advisory on Iranian Islamic Revolutionary Guard Corps-Affiliated Attacks
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
AvosLocker Ransomware Behavior Examined on Windows & Linux
blogs_qualys·2022-03-07·CVSS 7.6
[HIGH] AvosLocker Ransomware Behavior Examined on Windows & Linux
## Table of Contents
Technical Analysis of AvosLocker Windows Variant
Technical Analysis of AvosLocker Linux Variant
Indicators of Compromise (IOCs):
TTP Map:
AvosLocker is a ransomware group that was identified in 2021, specifically targeting Windows machines. Now a new variant of AvosLocker malware is also targeting Linux environments. In this blog, we examine the behavior of these two AvosLocker Ransomware in detail.
AvosLocker is a relatively new ransomware-as-a-service that was first spotted in late June 2021. The attackers use spam email campaigns as initial infection vectors for the delivery of the ransomware payload. During the encryption, process files are appended with the “.avos” extension. An updated variant appends with the extension “.avos2”. Similarly, the Linux versio
Qualys
AvosLocker Ransomware Behavior Examined on Windows & Linux | Qualys
blogs_qualys·2022-03-07
AvosLocker Ransomware Behavior Examined on Windows & Linux | Qualys
#### Table of Contents
- Technical Analysis of AvosLocker Windows Variant
- Technical Analysis of AvosLocker Linux Variant
- Indicators of Compromise (IOCs):
- TTP Map:
AvosLocker is a ransomware group that was identified in 2021, specifically targeting Windows machines. Now a new variant of AvosLocker malware is also targeting Linux environments. In this blog, we examine the behavior of these two AvosLocker Ransomware in detail.
AvosLocker is a relatively new ransomware-as-a-service that was first spotted in late June 2021. The attackers use spam email campaigns as initial infection vectors for the delivery of the ransomware payload. During the encryption, process files are appended with the “.avos” extension. An updated variant appends with the extension “.avos2”. Similarly, the Linux
Tenable
Microsoft’s July 2021 Patch Tuesday Includes 116 CVEs (CVE-2021-31979, CVE-2021-33771)
blogs_tenable·2021-07-13·CVSS 7.8
[HIGH] Microsoft’s July 2021 Patch Tuesday Includes 116 CVEs (CVE-2021-31979, CVE-2021-33771)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Crowdstrike
July 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] July 2021 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Sentinelone
AvosLocker
blogs_sentinelone
AvosLocker
# AvosLocker Ransomware: In-Depth Analysis, Detection, and Mitigation
## Summary of AvosLocker Ransomware
AvosLocker is one of the more recent ransomware families that came to fill the void left by REvil. It was first spotted in July 2021 and has since come up with several variants released over time. They also used this avenue to recruit additional team members and Initial Access Brokers (IABs). AvosLocker practices double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data. AvosLocker launched with support for Windows payloads only, however a Linux variant was later released.AvosLocker operates as a ransomware-as-a-service (RaaS) model, targeting organizations based on their ability to pay the demanded ransom. While less prominent or active than
Crowdstrike
July 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] July 2021 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2021-07-14
Published
Exploited in the wild