CVE-2021-31206
HIGH EXPLOITED IN THE WILD RANSOMWAREMicrosoft Exchange Server - Remote Code Execution
Title source: llmExploitation Summary
CVE-2021-31206 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io), including in ransomware campaigns.
Description
Microsoft Exchange Server Remote Code Execution Vulnerability
References (2)
Core 2
Core References
Patch, Vendor Advisory x_refsource_misc
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31206
Third Party Advisory, VDB Entry x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-21-826/
Scores
CVSS v3
7.6
EPSS
0.0979
EPSS Percentile
95.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
Details
VulnCheck KEV
2022-01-17
InTheWild.io
2022-05-25
Ransomware Use
Confirmed
Status
published
Products (3)
microsoft/exchange_server
2013 cumulative_update_23
microsoft/exchange_server
2016 cumulative_update_20 (2 CPE variants)
microsoft/exchange_server
2019 cumulative_update_10 (2 CPE variants)
Published
Jul 14, 2021
Tracked Since
Feb 18, 2026