CVE-2021-31196

HIGH KEV

Microsoft Exchange Server - Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-31196 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added August 21, 2024.

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

Scores

CVSS v3 7.2
EPSS 0.0334
EPSS Percentile 87.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2024-08-21
VulnCheck KEV 2022-09-14
InTheWild.io 2024-08-21
ENISA EUVD EUVD-2021-18109
Status published
Products (3)
microsoft/exchange_server 2013 cumulative_update_23
microsoft/exchange_server 2016 cumulative_update_20 (2 CPE variants)
microsoft/exchange_server 2019 cumulative_update_10 (2 CPE variants)
Published Jul 14, 2021
KEV Added Aug 21, 2024
Tracked Since Feb 18, 2026