Junglewise Threat Intelligence

CVE-2021-31207: Microsoft Exchange Server Security Feature Bypass Vulnerability

CVE-2021-31207 · Severity: critical · CVSS 6.6 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Exchange Server, Microsoft Exchange Server 2019, Microsoft Exchange Server 2016. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server contains a security feature bypass vulnerability due to unrestricted upload of files with dangerous types (CWE-434). This vulnerability is part of the 'ProxyShell' exploit chain and allows an authenticated attacker with high privileges to bypass security restrictions.

Affected products

  • Microsoft Exchange Server 2013 Cumulative Update 23
  • Microsoft Exchange Server 2016 Cumulative Update 19, Cumulative Update 20
  • Microsoft Exchange Server 2019 Cumulative Update 8, Cumulative Update 9

Timeline

  • 2021-05-11: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild in the advisory summary and CISA KEV catalog.

Related threats