CVE-2021-24085

MEDIUM

Microsoft Exchange Server - Spoofing

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-24085. PoCs published by sourceincite.

AI-analyzed exploit summary This repository contains a functional Proof of Concept (PoC) for CVE-2021-24085, which exploits a Cross-Site Request Forgery (CSRF) vulnerability in Microsoft Exchange Server to elevate privileges. The PoC includes tools to generate CSRF tokens and execute the exploit, demonstrating the vulnerability's mechanics.

Description

Microsoft Exchange Server Spoofing Vulnerability

Exploits (1)

nomisec WORKING POC 71 stars
by sourceincite · poc
https://github.com/sourceincite/CVE-2021-24085

This repository contains a functional Proof of Concept (PoC) for CVE-2021-24085, which exploits a Cross-Site Request Forgery (CSRF) vulnerability in Microsoft Exchange Server to elevate privileges. The PoC includes tools to generate CSRF tokens and execute the exploit, demonstrating the vulnerability's mechanics.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Exchange Server
Auth required
Prerequisites: Access to a target Exchange Server · Valid user credentials · Certificate with private key
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.1318
EPSS Percentile 94.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Details

Status published
Products (2)
microsoft/exchange_server 2016 cumulative_update_18 (2 CPE variants)
microsoft/exchange_server 2019 cumulative_update_7 (2 CPE variants)
Published Feb 25, 2021
Tracked Since Feb 18, 2026