CVE-2021-31207
Microsoft Exchange Server Security Feature Bypass Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
YesDecision
Descriptions
Microsoft Exchange Server Security Feature Bypass Vulnerability
Una vulnerabilidad de Omisión de la CaracterÃstica de Seguridad de Microsoft Exchange Server
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Exchange Server. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
The specific flaw exists within the handling of mailbox export. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute arbitrary code in the context of SYSTEM.
Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-04-14 CVE Reserved
- 2021-05-11 CVE Published
- 2021-11-03 Exploited in Wild
- 2021-11-17 KEV Due Date
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-10-14 EPSS Updated
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://www.zerodayinitiative.com/advisories/ZDI-21-819 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
http://packetstormsecurity.com/files/163895/Microsoft-Exchange-ProxyShell-Remote-Code-Execution.html | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31207 | 2023-08-08 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2013 Search vendor "Microsoft" for product "Exchange Server" and version "2013" | cumulative_update_23 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2016 Search vendor "Microsoft" for product "Exchange Server" and version "2016" | cumulative_update_19 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2016 Search vendor "Microsoft" for product "Exchange Server" and version "2016" | cumulative_update_20 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2019 Search vendor "Microsoft" for product "Exchange Server" and version "2019" | cumulative_update_8 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Exchange Server Search vendor "Microsoft" for product "Exchange Server" | 2019 Search vendor "Microsoft" for product "Exchange Server" and version "2019" | cumulative_update_9 |
Affected
|