CVE-2021-31207
Description
Microsoft Exchange Server Security Feature Bypass Vulnerability
In plain language
AI Act nowCVE-2021-31207 is a Microsoft Exchange Server flaw that bypasses a security check and has been used in real ransomware attacks, so most small businesses running vulnerable Exchange versions should act immediately by updating.
CVE-2021-31207 is a security feature bypass in Microsoft Exchange Server (2013/2016/2019 specific cumulative updates), enabling attackers to evade a protective check and then proceed with harmful actions; it has been confirmed exploited in ransomware campaigns and is listed in CISA KEV.
What to do now
- Check your Microsoft Exchange Server version (2013 CU 23, 2016 CUs 19/20, or 2019 CUs 8/9) to see if you are on one of the affected cumulative updates.
- If you are affected, upgrade Exchange to the fixed build for your branch: 2013 CU 23 → 15.00.1497.018.
- If you are affected, upgrade Exchange to the fixed build for your branch: 2016 CU 19 → 15.01.2176.014.
- If you are affected, upgrade Exchange to the fixed build for your branch: 2016 CU 20 → 15.01.2242.010.
- If you are affected, upgrade Exchange to the fixed build for your branch: 2019 CU 8 → 15.02.0792.015.
- If you are affected, upgrade Exchange to the fixed build for your branch: 2019 CU 9 → 15.02.0858.012.
- After updating, verify the Exchange servers are on the corrected versions and re-check for any active or suspicious ransomware activity in logs.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2021-31207 and every CVE in our database. Create a free account — no credit card required.
Create Free Account