Description
Microsoft Exchange Server Remote Code Execution Vulnerability
In plain language
AI Act nowThis is a Microsoft Exchange Server flaw that lets an attacker run code on your server; typical small businesses using affected Exchange versions should treat it as urgent and update immediately.
CVE-2021-27065 is a Microsoft Exchange Server remote code execution flaw (CWE-22) that is confirmed in the wild via CISA KEV and has public exploits available, meaning attackers can trigger it to take over an Exchange server remotely.
What to do now
- Check your Microsoft Exchange Server version against the affected list: Exchange Server 2013 CU 21/22/23, Exchange Server 2013 SP1, Exchange Server 2016 CU 10/11/12/13/14.
- Verify whether you’re reachable from the internet on Exchange services (common default for email), and confirm you haven’t already applied the fixed Exchange updates.
- Upgrade to the fixed version for your exact release line (see below).
- If you can’t upgrade right away, immediately isolate Exchange from external access and follow Microsoft’s mitigation guidance until you can patch.
- After patching, review Exchange and security logs for signs of compromise and hunt for suspicious persistence.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2021-27065 and every CVE in our database. Create a free account — no credit card required.
Create Free Account