Three Exchange flaws chain into unauthenticated RCE with SYSTEM privileges.
The 'Medium' Severity Trap. The final link (CVE-2021-31207) is rated only CVSS 6.6 (Medium) in isolation. A defender filtering logs solely by 'High/Critical' would ignore it, yet it acts as the payload delivery vehicle that awards full SYSTEM privileges.
Step-by-step exploitation flow. Each link compounds the next.
Exploits explicit path parsing discrepancies to bypass access control lists (ACLs) entirely.
Yielded Result: Unauthenticated access to the Exchange PowerShell backend interface.
Allows an authenticated user (now bypassed) to elevate their privileges inside the Exchange PowerShell execution context.
Yielded Result: Exchange Admin (SYSTEM) code execution authority.
Allows the authenticated/elevated session to write malicious payload files anywhere on the operating system.
Yielded Result: Web shell installation leading to persistent, unauthenticated SYSTEM RCE.
Unauthenticated Remote Code Execution (RCE) with SYSTEM privileges on internal mail servers.