Vulnerability record · CVE-2021-31195 · published 11 May 2021
CVE-2021-31195: Microsoft Exchange Server remote code execution flaw
Microsoft · Exchange Server
CVE-2021-31195 is a remote code execution vulnerability in Microsoft Exchange Server, per the vendor description. The record is thin: it gives no root-cause detail beyond a generic RCE label and a CWE entry for authentication bypass by spoofing, so the exact mechanism is not established by the supplied facts. It matters because Exchange is an internet-facing mail and collaboration service, and the CVSS vector indicates a network-reachable issue requiring user interaction.
Description
Microsoft Exchange Server Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe flaw is a network-reachable RCE in internet-facing Exchange with a very high EPSS score, though the record lacks KEV listing, exploit tags and technical detail.
What it is
CVE-2021-31195 is a remote code execution vulnerability in Microsoft Exchange Server, per the vendor description. The record is thin: it gives no root-cause detail beyond a generic RCE label and a CWE entry for authentication bypass by spoofing, so the exact mechanism is not established by the supplied facts. It matters because Exchange is an internet-facing mail and collaboration service, and the CVSS vector indicates a network-reachable issue requiring user interaction.
Impact
The stated impact is remote code execution, which would let an attacker run code in the context of the Exchange service. The CVSS vector scores only confidentiality as high (C:H/I:N/A:N), so the record does not substantiate integrity or availability effects.
Attack surface
Reachable over the network (AV:N) with no privileges required (PR:N), but user interaction is required (UI:R), so exploitation depends on a victim triggering the malicious action. No specific Exchange endpoint, protocol or component is named in the record.
Exploitation
Not listed in CISA KEV and no ransomware use is documented, but EPSS is very high at 0.73676 (99.4th percentile), indicating strong predicted exploitation activity. The only references are Microsoft patch and vendor advisory links, with no public exploit or in-the-wild reporting tags.
What to do
- Apply the Microsoft security update for CVE-2021-31195 referenced in the vendor advisory as the first action.
- Confirm Exchange Server builds are current, since this CVE was published alongside other Exchange fixes in the May 2021 cycle.
- Restrict external exposure of Exchange services (OWA, ECP, Autodiscover) to reduce reachable attack surface.
- Treat inbound mail and links as untrusted and reinforce user awareness, because the vector requires user interaction.
- Monitor for anomalous child processes or web-shell-like activity spawned by Exchange worker processes.
Detection
- Hunt for unexpected processes spawned by Exchange IIS or worker processes (w3wp.exe, MSExchange*) on mailbox and CAS servers.
- Review Exchange and IIS logs for unusual requests or authentication patterns around the time of suspected activity.
- Alert on new or modified files in Exchange web directories and on suspicious script files written there.
- Correlate endpoint telemetry for command-shell or scripting activity originating from Exchange service accounts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31195 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31195 | PatchVendor Advisory |
Track CVE-2021-31195 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-31195), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.