Junglewise Threat Intelligence

CVE-2021-31196: Microsoft Exchange Server Information Disclosure Vulnerability

CVE-2021-31196 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2024-08-21

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server contains a vulnerability that can lead to information disclosure or remote code execution. The flaw allows an authenticated attacker with high privileges to compromise the confidentiality, integrity, and availability of the system over a network.

Affected products

  • Microsoft Exchange Server 2013 Cumulative Update 23
  • Microsoft Exchange Server 2016 Cumulative Update 20
  • Microsoft Exchange Server 2016 Cumulative Update 21
  • Microsoft Exchange Server 2019 Cumulative Update 9
  • Microsoft Exchange Server 2019 Cumulative Update 10

Timeline

  • 2021-07-14: disclosed: NVD Published Date
  • 2021-07-16: patched: Initial analysis and patch references added by NIST/Microsoft
  • 2024-08-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-08-21: exploited: Reported as exploited in the wild per CISA KEV entry

Related threats