ZeroHour

CVE-2021-31196

KEVmass

Information Disclosure in Microsoft Exchange Server Exploited in the Wild

CISA: Microsoft Exchange Server Information Disclosure Vulnerability

CVSS 3.1
7.2 high
EPSS
54%p99
Published
()
KEV added
AI analysis

CVE-2021-31196 is a Microsoft Exchange Server vulnerability that CISA's catalog names as an information disclosure flaw (the associated description string calls it remote code execution), rated CVSS 3.1 7.2 (AV:N/AC:L/PR:H/UI:N), meaning it is exploitable over the network without user interaction but only by an attacker already holding high-privilege, admin-level credentials on the server. It is triggered by sending crafted requests to a vulnerable Exchange server using those elevated credentials, and the attacker gains access to protected information - or, per the remote code execution description, potentially code execution on the server. The CISA data lists Microsoft Exchange Server with no specific version ranges, so unpatched on-premises Exchange deployments should be presumed in scope, with internet-facing servers the most plausible targets. Exploitation is confirmed: CISA added the bug to the Known Exploited Vulnerabilities catalog on 2024-08-21 (ransomware use unknown), and EPSS assigns a 54% probability of exploitation within 30 days (99th percentile), although no public proof-of-concept is known.

What to do: Install the Microsoft Exchange security update for CVE-2021-31196 (shipped in the May 2021 Patch Tuesday Exchange security updates) or a later update on every Exchange server, prioritizing internet-facing ones, and verify installed builds rather than assuming the earlier 2021 Exchange patches covered this flaw. Given confirmed exploitation and reports of attackers actively scanning for unpatched Exchange servers, audit privileged-account usage and review logs for anomalous admin activity; federal agencies must remediate within the standard two-week BOD 22 window following the KEV listing. If immediate patching is not possible, restrict OWA/ECP exposure to trusted networks and enforce MFA and strong credentials for Exchange admin accounts, per CISA's required action.

Affected
Microsoft Exchange Server
Estimated exposure
masshundreds of thousands of on-premises Exchange servers worldwide, with ~250,000+ internet-exposed Exchange/OWA endpoints counted in public scans — Based on internet-wide scans of exposed Outlook Web Access/ECP endpoints (roughly 250,000 at the time of the March 2021 ProxyLogon response) and Exchange Server's very large installed base among mid-size and enterprise organizations.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Exchange Server
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
exchange server
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news