CVE-2021-31207highKEVEXPLOITRANSOMWAREZERO DAYSecurin Validate-Ready
Microsoft Exchange Server Security Feature Bypass Vulnerability
Microsoft Exchange Server Security Feature Bypass Vulnerability
Vulnerability Type
Improper Access Control
Impact Type
Authentication/Authorization Bypass
Vector
NETWORK
Affected Vendors
microsoft
Securin Risk Score
CVSS: 6.6
Vulnerability Timeline
- 💥1st Exploit Published
- 📋CVE Published
- 🛡️Securin KEV Published
- 📄NVD Published
- 🔮Securin Predicted
- 🏛️CISA KEV Published
- ←Securin Predicted → NVD Latency: Up to 1 Day→
- ←Securin Predicted → CISA Latency: 32 days→
- ←Securin Predicted → Exploit Latency: 179 days→
Threat Intelligence Summary
Microsoft Exchange Server Security Feature Bypass Vulnerability
Weaknesses
—
Threats
27
Threat Actor Associations
—
References
CVE
- https://www.cert.govt.nz/advisories/active-scanning-for-microsoft-exchange-proxyshell-vulnerability/
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-18120
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-31207
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31207
- https://www.cisa.gov/news-events/alerts/2021/08/21/urgent-protect-against-active-exploitation-proxyshell-vulnerabilities
- https://www.infosecurity-magazine.com/news/microsoft-exchange-server-zeroday/
- https://nvd.nist.gov/vuln/detail/CVE-2021-31207
- https://www.zerodayinitiative.com/advisories/ZDI-21-819/
- http://packetstormsecurity.com/files/163895/Microsoft-Exchange-ProxyShell-Remote-Code-Execution.html
- https://msrc.microsoft.com/update-guide/en-us/vulnerability/CVE-2021-31207
- https://news.sophos.com/en-us/2021/08/23/proxyshell-vulnerabilities-in-microsoft-exchange-what-to-do/
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31207
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-31207
- https://www.techtarget.com/whatis/feature/Everything-you-need-to-know-about-ProxyShell-vulnerabilities
Exploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://otx.alienvault.com/indicator/cve/CVE-2021-31207
- https://threatpost.com/apt-chamelgang-targets-russian-energy-aviation/175272/?web_view=true
- https://blog.qualys.com/vulnerabilities-threat-research/2022/03/06/avoslocker-ransomware-behavior-examined-on-windows-linux
- https://www.coresecurity.com/core-labs/exploits?exploit_name=Microsoft Exchange Proxyshell Remote Code Execution Vulnerability Exploit
- https://www.rapid7.com/db/modules/exploit/windows/http/exchange_proxyshell_rce
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:Win32/CVE-2021-31207!MTB&ThreatID=2147816487
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:Win32/CVE-2021-31207!rfn&ThreatID=2147797304
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:Win32/CVE-2021-31207.A&ThreatID=2147793809
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:Win32/CVE-2021-31207.B&ThreatID=2147794023
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:Win32/CVE-2021-31207.C&ThreatID=2147845571
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:Win32/CVE-2021-31207.HW!MTB&ThreatID=2147816378
- https://packetstormsecurity.com/files/163895/Microsoft-Exchange-ProxyShell-Remote-Code-Execution.html
Malware
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Behavior:Win32/SuspExchgSession.E&ThreatID=2147779829
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Ransom:Win32/Cuba.RMA!MTB&ThreatID=2147819636
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:Win32/IISExchgSpawnCMD.A&ThreatID=2147776639
- https://www.ransomware.live/group/karma
- https://www.zdnet.com/article/two-ransomware-gangs-hacked-the-same-target-at-the-same-time-heres-what-happened-next/
- https://www.ransomware.live/group/lv
- https://www.trendmicro.com/en_us/research/22/j/lv-ransomware-exploits-proxyshell-in-attack.html
- https://bitdefender.com/en-us/blog/hotforsecurity/ransomware-negotiator-working-other-side
- https://cloud.google.com/blog/topics/threat-intelligence/europe-data-leak-landscape
- https://cyberpress.org/florida-ransomware-negotiator-sentenced-blackcat-attacks/
- https://cyberpress.org/ransomware-shifts-to-data-theft/
- https://cybersecuritynews.com/hackers-weaponize-legitimate-windows-tools/
- https://securityaffairs.com/191100/security/ransomware-negotiator-caught-secretly-assisting-blackcat-extortion-scheme.html
- https://www.bleepingcomputer.com/news/security/former-ransomware-negotiator-pleads-guilty-to-blackcat-attacks/
- https://www.bleepingcomputer.com/news/security/us-charges-another-ransomware-negotiator-linked-to-blackcat-attacks/
- https://www.malwarebytes.com/blog/news/2026/07/the-inside-job-that-cost-ransomware-victims-millions
- https://www.ransomware.live/group/alphv
- https://www.varonis.com/blog/alphv-blackcat-ransomware
- https://blog.eclecticiq.com/the-analyst-prompt-39-ransomware-falsified-covid-certificates-us-blacklists-nso-group
- https://cyberpress.org/fortinet-flaws-fuel-ransomware/
- https://cybersecuritynews.com/conti-ransomware-hacker-sentenced/
- https://securityaffairs.com/195117/cyber-crime/ransomware-never-stopped-over-9000-confirmed-attacks-since-2018.html
- https://securityaffairs.com/198931/cyber-crime/conti-hacker-who-built-malware-and-attacked-victims-gets-four-year-sentence.html
- https://securityonline.info/conti-ransomware-guilty-plea/
- https://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-pleads-guilty-in-the-us-faces-15-years-in-prison/
- https://www.pcrisk.com/removal-guides/17011-conti-ransomware
- https://www.ransomware.live/group/conti
- https://www.ransomware.live/group/avoslocker
- https://unit42.paloaltonetworks.com/lockbit-2-ransomware/
- https://cybersecuritynews.com/ransomware-operators-disable-edr/
- https://redcanary.com/blog/blackbyte-ransomware/
- https://www.ransomware.live/group/blackbyte
- https://www.bleepingcomputer.com/news/security/microsoft-exchange-servers-hacked-to-deploy-hive-ransomware/
- https://www.ransomware.live/group/hive
- https://research.nccgroup.com/2023/11/20/is-this-the-real-life-is-this-just-fantasy-caught-in-a-landslide-noescape-from-ncc-group/
- https://www.ransomware.live/group/noescape
- https://thehackernews.com/2022/09/researchers-detail-emerging-cross.html
- https://www.ransomware.live/group/bianlian
- https://therecord.media/new-cring-ransomware-deployed-via-unpatched-fortinet-vpns/
- https://therecord.media/new-lockfile-ransomware-gang-weaponizes-proxyshell-and-petitpotam-attacks/
- https://www.bleepingcomputer.com/news/security/babuk-ransomware-is-back-uses-new-version-on-corporate-networks/
- https://www.ransomware.live/group/babuk
- https://www.ransomware.live/group/babuk2
- https://www.bleepingcomputer.com/news/security/microsoft-exchange-servers-hacked-to-deploy-cuba-ransomware/
- https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-flaws-exposing-backup-servers-to-rce-attacks/
- https://www.ransomware.live/group/cuba
Unlock the details for this CVE
Sign up with Securin to access the full AI summary, impacted products, exploitability details, threat intelligence, discussions and reference mappings for this CVE.
Unlock with Securin