CVE-2021-34473

CRITICAL KEV RANSOMWARE NUCLEI

Microsoft Exchange ProxyShell RCE

Title source: metasploit

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

Exploits (15)

nomisec WORKING POC 119 stars
by horizon3ai · remote
https://github.com/horizon3ai/proxyshell
nomisec SCANNER 47 stars
by cyberheartmi9 · remote
https://github.com/cyberheartmi9/Proxyshell-Scanner
nomisec WORKING POC 41 stars
by kh4sh3i · remote
https://github.com/kh4sh3i/ProxyShell
nomisec WORKING POC 30 stars
by p2-98 · poc
https://github.com/p2-98/CVE-2021-34473
nomisec WORKING POC 17 stars
by je6k · remote
https://github.com/je6k/CVE-2021-34473-Exchange-ProxyShell
nomisec SCANNER 6 stars
by RaouzRouik · poc
https://github.com/RaouzRouik/CVE-2021-34473-scanner
nomisec SCANNER 2 stars
by ipsBruno · infoleak
https://github.com/ipsBruno/CVE-2021-34473-NMAP-SCANNER
nomisec WORKING POC
by Loqueseamevaleverg · poc
https://github.com/Loqueseamevaleverg/ProxyHell
nomisec WORKING POC
by f4alireza · remote
https://github.com/f4alireza/CVE
metasploit WORKING POC EXCELLENT
by Orange Tsai, Jang (@testanull), PeterJson, brandonshi123, mekhalleh (RAMELLA Sébastien), Donny Maasland, Rich Warren, Spencer McIntyre, wvu · rubypocwindows
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/exchange_proxyshell_rce.rb
patchapalooza SCANNER
by learningsurface · remote
https://github.com/learningsurface/ProxyShell-CVE-2021-34473.py
patchapalooza WORKING POC
by aravazhimdr · remote
https://github.com/aravazhimdr/ProxyShell-POC-Mod
patchapalooza WORKING POC
by Udyz · remote
https://github.com/Udyz/proxyshell-auto
patchapalooza WORKING POC
by dmaasland · remote
https://github.com/dmaasland/proxyshell-poc
patchapalooza WORKING POC
by ktecv2000 · remote
https://github.com/ktecv2000/ProxyShell

Nuclei Templates (1)

Exchange Server - Remote Code Execution
CRITICALby arcc,intx0x80,dwisiswant0,r3dg33k
Shodan: vuln:cve-2021-26855 || http.favicon.hash:1768726119 || http.title:"outlook" || cpe:"cpe:2.3:a:microsoft:exchange_server"
FOFA: title="outlook" || icon_hash=1768726119

Scores

CVSS v3 9.1
EPSS 0.9419
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-08-30
InTheWild.io 2021-08-24
ENISA EUVD EUVD-2021-21128
Ransomware Use Confirmed
CWE
CWE-918
Status published
Products (3)
microsoft/exchange_server 2013 cumulative_update_23
microsoft/exchange_server 2016 cumulative_update_19 (2 CPE variants)
microsoft/exchange_server 2019 cumulative_update_8 (2 CPE variants)
Published Jul 14, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026