CVE-2021-34473criticalKEVEXPLOITRANSOMWAREZERO DAYSecurin Validate-Ready
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
Vulnerability Type
Code Injection
Impact Type
Code Execution
Vector
NETWORK
Affected Vendors
microsoft
Securin Risk Score
CVSS: 9.8
Vulnerability Timeline
- 💥1st Exploit Published
- 📋CVE Published
- 🛡️Securin KEV Published
- 📄NVD Published
- 🔮Securin Predicted
- 🏛️CISA KEV Published
- ←Securin Predicted → NVD Latency: 1 day→
- ←Securin Predicted → CISA Latency: 85 days→
- ←Securin Predicted → Exploit Latency: 126 days→
Threat Intelligence Summary
Microsoft Exchange Server Remote Code Execution Vulnerability
Weaknesses
—
Threats
33
Threat Actor Associations
—
References
CVE
- https://www.cert.govt.nz/advisories/active-scanning-for-microsoft-exchange-proxyshell-vulnerability/
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-21128
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34473
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34473
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-34473.yaml
- https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2021-patch-tuesday-fixes-9-zero-days-117-flaws/
- https://www.cisa.gov/news-events/alerts/2021/08/21/urgent-protect-against-active-exploitation-proxyshell-vulnerabilities
- https://nvd.nist.gov/vuln/detail/CVE-2021-34473
- https://www.zerodayinitiative.com/advisories/ZDI-21-821/
- http://packetstormsecurity.com/files/163895/Microsoft-Exchange-ProxyShell-Remote-Code-Execution.html
- https://blog.orange.tw/2021/08/proxylogon-a-new-attack-surface-on-ms-exchange-part-1.html
- https://news.sophos.com/en-us/2021/08/23/proxyshell-vulnerabilities-in-microsoft-exchange-what-to-do/
- https://peterjson.medium.com/reproducing-the-proxyshell-pwn2own-exploit-49743a4ea9a1
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34473
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-34473
- https://www.techtarget.com/whatis/feature/Everything-you-need-to-know-about-ProxyShell-vulnerabilities
Exploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://otx.alienvault.com/indicator/cve/CVE-2021-34473
- https://www.microsoft.com/en-us/security/blog/2023/03/24/guidance-for-investigating-attacks-using-cve-2023-23397/
- https://blog.qualys.com/vulnerabilities-threat-research/2022/03/06/avoslocker-ransomware-behavior-examined-on-windows-linux
- https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/monitoring/?category=monitoring&statistic=unique_ips&d1=2026-08-12&d2=2026-08-12
- https://github.com/Loqueseamevaleverg/ProxyHell
- https://github.com/RaouzRouik/CVE-2021-34473-scanner
- https://github.com/cyberheartmi9/Proxyshell-Scanner
- https://github.com/f4alireza/CVE
- https://github.com/horizon3ai/proxyshell
- https://github.com/ipsBruno/CVE-2021-34473-NMAP-SCANNER
- https://github.com/je6k/CVE-2021-34473-Exchange-ProxyShell
- https://github.com/kh4sh3i/ProxyShell
- https://github.com/learningsurface/ProxyShell-CVE-2021-34473.py
- https://github.com/p2-98/CVE-2021-34473
- https://www.rapid7.com/db/modules/exploit/windows/http/exchange_proxyshell_rce
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:Script/CVE-2021-34473.A&ThreatID=2147833011
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:Script/CVE-2021-34473.B&ThreatID=2147833031
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:Win32/CVE-2021-31207.A&ThreatID=2147793809
- https://packetstormsecurity.com/files/163895/Microsoft-Exchange-ProxyShell-Remote-Code-Execution.html
Malware
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Behavior:Win32/CVE-2021-34473.A&ThreatID=2147787745
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Behavior:Win32/SuspExchgSession.E&ThreatID=2147779829
- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:Win32/IISExchgSpawnCMD.A&ThreatID=2147776639
- https://www.ransomware.live/group/karma
- https://www.zdnet.com/article/two-ransomware-gangs-hacked-the-same-target-at-the-same-time-heres-what-happened-next/
- https://www.ransomware.live/group/lv
- https://www.trendmicro.com/en_us/research/22/j/lv-ransomware-exploits-proxyshell-in-attack.html
- https://bitdefender.com/en-us/blog/hotforsecurity/ransomware-negotiator-working-other-side
- https://cloud.google.com/blog/topics/threat-intelligence/europe-data-leak-landscape
- https://cyberpress.org/florida-ransomware-negotiator-sentenced-blackcat-attacks/
- https://cyberpress.org/ransomware-shifts-to-data-theft/
- https://cybersecuritynews.com/hackers-weaponize-legitimate-windows-tools/
- https://securityaffairs.com/191100/security/ransomware-negotiator-caught-secretly-assisting-blackcat-extortion-scheme.html
- https://www.bleepingcomputer.com/news/security/former-ransomware-negotiator-pleads-guilty-to-blackcat-attacks/
- https://www.bleepingcomputer.com/news/security/us-charges-another-ransomware-negotiator-linked-to-blackcat-attacks/
- https://www.malwarebytes.com/blog/news/2026/07/the-inside-job-that-cost-ransomware-victims-millions
- https://www.ransomware.live/group/alphv
- https://www.varonis.com/blog/alphv-blackcat-ransomware
- https://blog.eclecticiq.com/the-analyst-prompt-39-ransomware-falsified-covid-certificates-us-blacklists-nso-group
- https://cyberpress.org/fortinet-flaws-fuel-ransomware/
- https://cybersecuritynews.com/conti-ransomware-hacker-sentenced/
- https://securityaffairs.com/195117/cyber-crime/ransomware-never-stopped-over-9000-confirmed-attacks-since-2018.html
- https://securityaffairs.com/198931/cyber-crime/conti-hacker-who-built-malware-and-attacked-victims-gets-four-year-sentence.html
- https://securityonline.info/conti-ransomware-guilty-plea/
- https://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-pleads-guilty-in-the-us-faces-15-years-in-prison/
- https://www.pcrisk.com/removal-guides/17011-conti-ransomware
- https://www.ransomware.live/group/conti
- https://www.ransomware.live/group/avoslocker
- https://unit42.paloaltonetworks.com/lockbit-2-ransomware/
- https://cybersecuritynews.com/ransomware-operators-disable-edr/
- https://redcanary.com/blog/blackbyte-ransomware/
- https://www.ransomware.live/group/blackbyte
- https://www.bleepingcomputer.com/news/security/microsoft-exchange-servers-hacked-to-deploy-hive-ransomware/
- https://www.ransomware.live/group/hive
- https://research.nccgroup.com/2023/11/20/is-this-the-real-life-is-this-just-fantasy-caught-in-a-landslide-noescape-from-ncc-group/
- https://www.ransomware.live/group/noescape
- https://thehackernews.com/2022/09/researchers-detail-emerging-cross.html
- https://www.ransomware.live/group/bianlian
- https://therecord.media/new-cring-ransomware-deployed-via-unpatched-fortinet-vpns/
- https://therecord.media/new-lockfile-ransomware-gang-weaponizes-proxyshell-and-petitpotam-attacks/
- https://www.bleepingcomputer.com/news/security/babuk-ransomware-is-back-uses-new-version-on-corporate-networks/
- https://www.ransomware.live/group/babuk
- https://www.ransomware.live/group/babuk2
- https://www.bleepingcomputer.com/news/security/microsoft-exchange-servers-hacked-to-deploy-cuba-ransomware/
- https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-flaws-exposing-backup-servers-to-rce-attacks/
- https://www.ransomware.live/group/cuba
Fix
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-34473
- https://www.tenable.com/plugins/nessus/152458
- https://www.tenable.com/plugins/nessus/148476
- https://www.checkpoint.com/defense/advisories/public/2021/cpai-2021-0476.html
- http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-202107-741
Unlock the details for this CVE
Sign up with Securin to access the full AI summary, impacted products, exploitability details, threat intelligence, discussions and reference mappings for this CVE.
Unlock with Securin