cbcvebase.
CVE-2021-31206
published 2021-07-14

CVE-2021-31206: Microsoft Exchange Server Remote Code Execution Vulnerability

PriorityP181high8CVSS 3.1
AVAACLPRNUIRSUCHIHAH
ITWEXPLOITVulnCheck KEVRansomware
Exploited in the wild
EPSS
9.79%
95.0th percentile
Microsoft Exchange Server Remote Code Execution Vulnerability

Affected

13 ranges
VendorProductVersion rangeFixed in
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftmicrosoft_exchange_server_2013_cumulative_update_23>= 15.00.0 < 15.00.1497.02315.00.1497.023
microsoftmicrosoft_exchange_server_2016_cumulative_update_20>= 15.01.0 < 15.01.2242.01215.01.2242.012
microsoftmicrosoft_exchange_server_2016_cumulative_update_21>= 15.01.0 < 15.01.2308.01415.01.2308.014
microsoftmicrosoft_exchange_server_2019_cumulative_update_10>= 15.02.0 < 15.02.0922.01315.02.0922.013
microsoftmicrosoft_exchange_server_2019_cumulative_update_9>= 15.02.0 < 15.02.0858.01515.02.0858.015
msrcmicrosoft_exchange_server_2013_cumulative_update_23
msrcmicrosoft_exchange_server_2016_cumulative_update_20
msrcmicrosoft_exchange_server_2016_cumulative_update_21
msrcmicrosoft_exchange_server_2019_cumulative_update_10
msrcmicrosoft_exchange_server_2019_cumulative_update_9

Detection & IOCsextracted from sources · hover to see the quote

hashC0A42741EEF72991D9D0EE8B6C0531FC19151457A8B59BDCF7B6373D1FE56E02
hash7C935DCD672C4854495F41008120288E8E1C144089F1F06A23BD0A0F52A544B1
urlhxxp://avosjon4pfh3y7ew3jdwz6ofw7lljcxlbk7hcxxmnxlh5kvf2akcqjad[.]onion
urlhxxp://avosqxh72b5ia23dl5fgwcpndkctuzqvh2iefk5imp3pi5gfhel5klad[.]onion
url{{BaseURL}}/autodiscover/[email protected]/owa/?&Email=autodiscover/autodiscover.json%[email protected]
url{{BaseURL}}/autodiscover/[email protected]/mapi/nspi/?&Email=autodiscover/autodiscover.json%[email protected]
otherExchange MAPI/HTTP Connectivity Endpoint
  • Probe Exchange /autodiscover/autodiscover.json endpoint with @-prefixed email parameter to detect ProxyShell SSRF (CVE-2021-31206 exploit chain). Response body containing 'OwaADUserNotFoundException' or 'Exchange MAPI/HTTP Connectivity Endpoint' indicates a vulnerable/exploited server.
  • CVE-2021-31206 is part of the ProxyShell exploit chain (alongside CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) used by AvosLocker for initial access to Microsoft Exchange; monitor Exchange IIS logs for autodiscover endpoint abuse with @-prefixed parameters.
  • ·The Nuclei template probe paths use '{{BaseURL}}' as a placeholder; substitute with the actual Exchange server base URL when operationalizing detection.
  • ·The Qualys IOC report truncates the Windows SHA-256 hash in one instance; the full hash C0A42741EEF72991D9D0EE8B6C0531FC19151457A8B59BDCF7B6373D1FE56E02 is confirmed in the complete IOC section.
  • ·Microsoft's advisory states exploit status as 'Exploited: No' and 'Publicly Disclosed: No' at time of publication; however, threat actors (AvosLocker) have since weaponized this CVE as part of the ProxyShell chain in real-world attacks.

CVSS provenance

nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.9HIGHAV:A/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.6HIGH
vendor_msrc7.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.