CVE-2021-34523
KEV ransomware PoC mass1Privilege Escalation in Microsoft Exchange Server (ProxyShell)
CISA: Microsoft Exchange Server Privilege Escalation Vulnerability
On-premises Microsoft Exchange Server contains an elevation-of-privilege flaw (CWE-287, improper authentication) in which Exchange performs an incorrect lookup of security descriptors for requests proxied to the Exchange PowerShell API. The flaw is reached through the Autodiscover endpoint and was published as the middle step of the 'ProxyShell' attack chain, where an unauthenticated attacker chains it with an SSRF bug (CVE-2021-34473) and a post-authentication RCE (CVE-2021-33768) to move from no access to running arbitrary code on the server. Successful exploitation lets an attacker impersonate a privileged Exchange account, gaining elevated privileges in the Exchange organization and, when chained, arbitrary code execution on the Exchange host. Any on-premises Exchange deployment is affected (Microsoft's advisory covers Exchange Server 2013, 2016, and 2019), with the greatest risk on servers whose Autodiscover/OWA endpoints are reachable from the internet. Exploitation is confirmed in the wild — the flaw is on CISA's KEV catalog (added 2021-11-03) with known ransomware use and an EPSS probability of 100% — even though no public proof-of-concept is known.
What to do: Apply Microsoft's July 2021 Exchange Server security updates for Exchange 2013, 2016, and 2019 as CISA's required action directs, prioritizing internet-facing servers given known ransomware use. Reduce exposure of Autodiscover/OWA endpoints (restrict to VPN or trusted networks where possible) and review IIS logs for suspicious requests to autodiscover/PowerShell endpoints as evidence of prior ProxyShell exploitation.
| Microsoft Exchange Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Exchange Server Elevation of Privilege Vulnerability
- Affected
- Microsoft Exchange Server
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- exchange server
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N