CVE-2021-31207

MEDIUM KEV RANSOMWARE

Microsoft Exchange Server - Security Feature Bypass via Unrestricted File Upload

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-31207 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021, with confirmed use in ransomware campaigns. EIP tracks 7 public exploits from researchers including Orange Tsai, Jang (@testanull), PeterJson, brandonshi123, mekhalleh (RAMELLA Sébastien), Donny Maasland, Rich Warren, Spencer McIntyre, wvu, horizon3ai, aravazhimdr, including a Metasploit module exploits/windows/http/exchange_proxyshell_rce.

AI-analyzed exploit summary This Metasploit module exploits the ProxyShell vulnerability chain (CVE-2021-31207, CVE-2021-34523, CVE-2021-34473) in Microsoft Exchange Server to achieve unauthenticated remote code execution by bypassing authentication, impersonating users, and writing arbitrary files.

Description

Microsoft Exchange Server Security Feature Bypass Vulnerability

Exploits (7)

metasploit WORKING POC EXCELLENT
by Orange Tsai, Jang (@testanull), PeterJson, brandonshi123, mekhalleh (RAMELLA Sébastien), Donny Maasland, Rich Warren, Spencer McIntyre, wvu · rubypocwindows
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/exchange_proxyshell_rce.rb

This Metasploit module exploits the ProxyShell vulnerability chain (CVE-2021-31207, CVE-2021-34523, CVE-2021-34473) in Microsoft Exchange Server to achieve unauthenticated remote code execution by bypassing authentication, impersonating users, and writing arbitrary files.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Exchange Server (2013 CU23 < 15.0.1497.15, 2016 CU19 < 15.1.2176.12, 2016 CU20 < 15.1.2242.5, 2019 CU8 < 15.2.792.13, 2019 CU9 < 15.2.858.9)
No auth needed
Prerequisites: Network access to Exchange Server · Exchange Server with vulnerable versions
devstral-2 · analyzed Apr 24, 2026 Full analysis →
patchapalooza WORKING POC
by horizon3ai · remote
https://github.com/horizon3ai/proxyshell

This repository contains a functional exploit for the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) affecting Microsoft Exchange Server. The exploit automates the attack chain to achieve unauthenticated remote code execution by leveraging authentication bypass and arbitrary file write vulnerabilities.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Exchange Server (2013, 2016, 2019)
No auth needed
Prerequisites: Network access to vulnerable Exchange Server · Unpatched Exchange Server (pre-July 2021 updates)
devstral-2 · analyzed Feb 23, 2026 Full analysis →
patchapalooza WORKING POC
by aravazhimdr · remote
https://github.com/aravazhimdr/ProxyShell-POC-Mod

This repository contains a functional exploit for the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) targeting Microsoft Exchange Server. The exploit merges two existing PoCs to achieve remote code execution by leveraging authentication bypass and arbitrary file write vulnerabilities.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Exchange Server 2016/2019
No auth needed
Prerequisites: Network access to vulnerable Exchange server · Valid email address on the target server
devstral-2 · analyzed Feb 23, 2026 Full analysis →
patchapalooza WORKING POC
by Udyz · remote
https://github.com/Udyz/proxyshell-auto

This repository contains a functional exploit for CVE-2021-31207, targeting Microsoft Exchange Server via the ProxyShell vulnerability chain. It includes scripts to automate the exploitation process, delivering a webshell for remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Exchange Server
No auth needed
Prerequisites: Network access to vulnerable Exchange server · Python environment with required dependencies
devstral-2 · analyzed Feb 23, 2026 Full analysis →
patchapalooza WORKING POC
by dmaasland · remote
https://github.com/dmaasland/proxyshell-poc

This repository contains functional exploit code for CVE-2021-31207, demonstrating ProxyShell vulnerabilities in Microsoft Exchange Server. The scripts include enumeration and RCE capabilities, leveraging autodiscover and EWS endpoints.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Exchange Server
No auth needed
Prerequisites: Network access to vulnerable Exchange Server · Python 3.8 or higher
devstral-2 · analyzed Feb 23, 2026 Full analysis →
patchapalooza WORKING POC
by ktecv2000 · remote
https://github.com/ktecv2000/ProxyShell

This repository contains a functional exploit for CVE-2021-31207, part of the ProxyShell vulnerability chain affecting Microsoft Exchange Server. The exploit demonstrates an authentication bypass and remote code execution by chaining SSRF and PowerShell remoting attacks.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Exchange Server (2013, 2016, 2019)
No auth needed
Prerequisites: network access to Exchange Server · valid email address on the target server
devstral-2 · analyzed Feb 23, 2026 Full analysis →
patchapalooza SCANNER
by cyberheartmi9 · infoleak
https://github.com/cyberheartmi9/Proxyshell-Scanner

This repository contains a scanner for detecting the Proxyshell vulnerability (CVE-2021-31207) in Microsoft Exchange Server. It includes a Python script and a Nuclei template to check for the presence of the vulnerability by sending a crafted request and checking for specific headers in the response.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Exchange Server
No auth needed
Prerequisites: network access to the target Exchange Server
devstral-2 · analyzed Feb 23, 2026 Full analysis →

Scores

CVSS v3 6.6
EPSS 0.9384
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-08-30
InTheWild.io 2021-08-24
ENISA EUVD EUVD-2021-18120
Ransomware Use Confirmed
CWE
CWE-434
Status published
Products (3)
microsoft/exchange_server 2013 cumulative_update_23
microsoft/exchange_server 2016 cumulative_update_19 (2 CPE variants)
microsoft/exchange_server 2019 cumulative_update_8 (2 CPE variants)
Published May 11, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026