CVE Tools

Description

Microsoft Exchange Server Security Feature Bypass Vulnerability

In plain language

AI Act now

CVE-2021-31207 is a Microsoft Exchange Server flaw that bypasses a security check and has been used in real ransomware attacks, so most small businesses running vulnerable Exchange versions should act immediately by updating.

Executive summary

CVE-2021-31207 is a security feature bypass in Microsoft Exchange Server (2013/2016/2019 specific cumulative updates), enabling attackers to evade a protective check and then proceed with harmful actions; it has been confirmed exploited in ransomware campaigns and is listed in CISA KEV.

If affected, business impact
Ransomware deployment riskEmail and account compromiseComplete business disruptionLoss of sensitive business data

What to do now

  1. Check your Microsoft Exchange Server version (2013 CU 23, 2016 CUs 19/20, or 2019 CUs 8/9) to see if you are on one of the affected cumulative updates.
  2. If you are affected, upgrade Exchange to the fixed build for your branch: 2013 CU 23 → 15.00.1497.018.
  3. If you are affected, upgrade Exchange to the fixed build for your branch: 2016 CU 19 → 15.01.2176.014.
  4. If you are affected, upgrade Exchange to the fixed build for your branch: 2016 CU 20 → 15.01.2242.010.
  5. If you are affected, upgrade Exchange to the fixed build for your branch: 2019 CU 8 → 15.02.0792.015.
  6. If you are affected, upgrade Exchange to the fixed build for your branch: 2019 CU 9 → 15.02.0858.012.
  7. After updating, verify the Exchange servers are on the corrected versions and re-check for any active or suspicious ransomware activity in logs.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:HPR:HUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:HAttack Complexity
High
PR:HPrivileges Required
High
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Nov 3, 2021
Remediation due:Nov 17, 2021
Ransomware:Known ransomware use

Required action: Apply updates per vendor instructions.

1 exploit source identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

3 techniques
Command and Control
Initial Access
Persistence
View detailed technique mapping

References

and 5 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2021-31207 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store