ZeroHour

CVE-2021-34523

KEV ransomware PoC mass1

Privilege Escalation in Microsoft Exchange Server (ProxyShell)

CISA: Microsoft Exchange Server Privilege Escalation Vulnerability

CVSS 3.1
9.0 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

On-premises Microsoft Exchange Server contains an elevation-of-privilege flaw (CWE-287, improper authentication) in which Exchange performs an incorrect lookup of security descriptors for requests proxied to the Exchange PowerShell API. The flaw is reached through the Autodiscover endpoint and was published as the middle step of the 'ProxyShell' attack chain, where an unauthenticated attacker chains it with an SSRF bug (CVE-2021-34473) and a post-authentication RCE (CVE-2021-33768) to move from no access to running arbitrary code on the server. Successful exploitation lets an attacker impersonate a privileged Exchange account, gaining elevated privileges in the Exchange organization and, when chained, arbitrary code execution on the Exchange host. Any on-premises Exchange deployment is affected (Microsoft's advisory covers Exchange Server 2013, 2016, and 2019), with the greatest risk on servers whose Autodiscover/OWA endpoints are reachable from the internet. Exploitation is confirmed in the wild — the flaw is on CISA's KEV catalog (added 2021-11-03) with known ransomware use and an EPSS probability of 100% — even though no public proof-of-concept is known.

What to do: Apply Microsoft's July 2021 Exchange Server security updates for Exchange 2013, 2016, and 2019 as CISA's required action directs, prioritizing internet-facing servers given known ransomware use. Reduce exposure of Autodiscover/OWA endpoints (restrict to VPN or trusted networks where possible) and review IIS logs for suspicious requests to autodiscover/PowerShell endpoints as evidence of prior ProxyShell exploitation.

Affected
Microsoft Exchange Server
Estimated exposure
mass≈300,000+ internet-exposed on-premises Exchange servers (order of hundreds of thousands in public internet scans around disclosure) — Shodan and other internet-wide scans at the time of the ProxyShell disclosures counted roughly 300,000-400,000 Exchange servers exposing OWA/Autodiscover, and Microsoft Exchange remains one of the most widely deployed on-prem mail…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Exchange Server Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Exchange Server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
exchange server
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

In the news