CVE-2021-27065highKEVEXPLOITRANSOMWAREZERO DAYSecurin Validate-Ready
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
Vulnerability Type
Code Injection
Impact Type
Code Execution
Vector
LOCAL
Affected Vendors
microsoft
Securin Risk Score
CVSS: 7.8
Vulnerability Timeline
- 📋CVE Published
- 💥1st Exploit Published
- 🛡️Securin KEV Published
- 📄NVD Published
- 🔮Securin Predicted
- 🏛️CISA KEV Published
- ←Securin Predicted → NVD Latency: 1 day→
- ←Securin Predicted → CISA Latency: 243 days→
- ←Securin Predicted → Exploit Latency: 4 days→
Threat Intelligence Summary
Microsoft Exchange Server Remote Code Execution Vulnerability
Weaknesses
—
Threats
54
Threat Actor Associations
—
References
CVE
- https://ccb.belgium.be/advisories/multiple-critical-vulnerabilities-microsoft-exchange
- https://cert.europa.eu/publications/security-advisories/2021-013/
- https://www.hkcert.org/security-bulletin/microsoft-monthly-security-update-march-2021-_20210310
- https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES02&VLCODE=CIAD-2021-0012
- https://www.jpcert.or.jp/english/at/2021/at210012.txt
- https://www.zero-day.cz/database/609/
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-13836
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-27065
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27065
- https://nvd.nist.gov/vuln/detail/CVE-2021-27065
- http://packetstormsecurity.com/files/161938/Microsoft-Exchange-ProxyLogon-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/162736/Microsoft-Exchange-ProxyLogon-Collector.html
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-27065
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27065
- https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
Exploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.welivesecurity.com/2021/03/10/exchange-servers-under-siege-10-apt-groups/
- https://www.mcafee.com/enterprise/en-us/assets/reports/rp-babuk-moving-to-vm-nix-systems.pdf
- https://cxsecurity.com/issue/WLB-2021030171
- https://cxsecurity.com/issue/WLB-2021050123
- https://www.exploit-db.com/exploits/49637
- https://github.com/adamrpostjr/cve-2021-27065
- https://www.rapid7.com/db/modules/exploit/windows/http/exchange_proxylogon_rce
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:ASP/CVE-2021-27065!MSR&ThreatID=2147788468
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:ASP/CVE-2021-27065!dha&ThreatID=2147954866
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:ASP/CVE-2021-27065!rfn&ThreatID=2147947840
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:ASP/CVE-2021-27065&ThreatID=2147776820
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:ASP/CVE-2021-27065.B!dha
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:ASP/CVE-2021-27065.C&ThreatID=2147795440
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:Script/Exmann.A!dha&ThreatID=2147776263
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:Win32/CVE-2021-27065&ThreatID=2147777919
- https://packetstormsecurity.com/files/161938/Microsoft-Exchange-ProxyLogon-Remote-Code-Execution.html
- https://packetstormsecurity.com/files/162736/Microsoft-Exchange-ProxyLogon-Collector.html
Malware
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper!MSR
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper!MTB
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper!dha
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper!rfn&ThreatID=2147830572
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.AA!dha
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.AY!dha
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.AZ!dha
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.D!dha
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.DA
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.E!dha
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.Ex!dha
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.F
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.F!dha
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.F!dha&ThreatID=2147776280
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:ASP/Chopper.G
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:Win64/GoDropper.A&ThreatID=2147778611
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Behavior:Win32/CVE-2021-27065.A&ThreatID=2147776976
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Behavior:Win32/Exmann.A&ThreatID=2147773895
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Behavior:Win32/Exmann.B&ThreatID=2147773896
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Behavior:Win32/IISExchgSpawnEMS.A&ThreatID=2147754368
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:PowerShell/LemonDuck.A&ThreatID=2147777717
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:PowerShell/LemonDuck.B&ThreatID=2147777719
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:PowerShell/LemonDuck.C&ThreatID=2147778209
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:PowerShell/LemonDuck.D&ThreatID=2147778221
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:PowerShell/LemonDuck.E&ThreatID=2147778476
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:PowerShell/LemonDuck.F&ThreatID=2147778477
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:PowerShell/LemonDuck.G&ThreatID=2147778478
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:PowerShell/Redearps.A&ThreatID=2147778205
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:Win32/IISExchgSpawnCMD.A&ThreatID=2147776639
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:Win32/LemonDuck.A&ThreatID=2147777720
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=TrojanDownloader:Linux/LemonDuck.G!MSR&ThreatID=2147765978
- https://bitdefender.com/en-us/blog/hotforsecurity/ransomware-negotiator-working-other-side
- https://cloud.google.com/blog/topics/threat-intelligence/europe-data-leak-landscape
- https://cyberpress.org/florida-ransomware-negotiator-sentenced-blackcat-attacks/
- https://cyberpress.org/ransomware-shifts-to-data-theft/
- https://cybersecuritynews.com/hackers-weaponize-legitimate-windows-tools/
- https://securityaffairs.com/191100/security/ransomware-negotiator-caught-secretly-assisting-blackcat-extortion-scheme.html
- https://www.bleepingcomputer.com/news/security/former-ransomware-negotiator-pleads-guilty-to-blackcat-attacks/
- https://www.bleepingcomputer.com/news/security/us-charges-another-ransomware-negotiator-linked-to-blackcat-attacks/
- https://www.malwarebytes.com/blog/news/2026/07/the-inside-job-that-cost-ransomware-victims-millions
- https://www.ransomware.live/group/alphv
- https://www.varonis.com/blog/alphv-blackcat-ransomware
- https://cybersecuritynews.com/ransomware-operators-disable-edr/
- https://www.bleepingcomputer.com/news/security/black-kingdom-ransomware-hacks-networks-with-pulse-vpn-flaws/
- https://redcanary.com/blog/blackbyte-ransomware/
- https://www.ransomware.live/group/blackbyte
- https://digital.nhs.uk/cyber-alerts/2021/cc-3874
- https://www.bleepingcomputer.com/news/security/babuk-ransomware-is-back-uses-new-version-on-corporate-networks/
- https://www.ransomware.live/group/babuk
- https://www.ransomware.live/group/babuk2
- https://www.bleepingcomputer.com/news/security/microsoft-exchange-servers-hacked-to-deploy-cuba-ransomware/
- https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-flaws-exposing-backup-servers-to-rce-attacks/
- https://www.ransomware.live/group/cuba
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Ransom:Win32/DoejoCrypt.A&ThreatID=2147777392
Unlock the details for this CVE
Sign up with Securin to access the full AI summary, impacted products, exploitability details, threat intelligence, discussions and reference mappings for this CVE.
Unlock with Securin