⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply updates per vendor instructions.. Due date: 2021-11-17.
Severity
6.6MEDIUM
EPSS
93.8%
top 0.14%
CISA KEV
KEVRansomware
Added 2021-11-03
Due 2021-11-17
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedMay 11
KEV addedNov 3
KEV dueNov 17
Latest updateJul 30
CISA Required Action: Apply updates per vendor instructions.

Description

Microsoft Exchange Server Security Feature Bypass Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.7 | Impact: 5.9

Affected Packages6 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-jcxv-6f65-7hrx: Microsoft Exchange Server Security Feature Bypass Vulnerability2022-05-24
CVEList
Microsoft Exchange Server Security Feature Bypass Vulnerability2021-05-11
VulnCheck
Microsoft Exchange Server Security Feature Bypass Vulnerability2021

💥Exploits & PoCs

1
Metasploit
Microsoft Exchange ProxyShell RCE

🔍Detection Rules

5
Suricata
ET EXPLOIT Microsoft Exchange SUID Disclosure via SSRF Inbound M2 (CVE-2021-31207)2022-03-29
Suricata
ET EXPLOIT Microsoft Exchange SUID Disclosure via SSRF Inbound M1 (CVE-2021-31207)2021-08-10
Suricata
ET EXPLOIT Vulnerable Microsoft Exchange Server Response (CVE-2021-31207)2021-08-09
Suricata
ET EXPLOIT Microsoft Exchange Pre-Auth Path Confusion M1 (CVE-2021-31207)2021-08-09
Suricata
ET EXPLOIT Microsoft Exchange Pre-Auth Path Confusion M2 (CVE-2021-31207)2021-08-09

📋Vendor Advisories

2
CISA
Microsoft Exchange Server Security Feature Bypass Vulnerability2021-11-03
Microsoft
Microsoft Exchange Server Security Feature Bypass Vulnerability2021-05-11

🕵️Threat Intelligence

3
Bleepingcomputer
UK govt links 2021 Electoral Commission breach to Exchange server2024-07-30
Elastic
Detection and response for the actively exploited ProxyShell vulnerabilities — Elastic Security Labs2022-06-02
Elastic
Detection and response for the actively exploited ProxyShell vulnerabilities — Elastic Security Labs2022-06-02