← Vulnerability feed

Vulnerability record · CVE-2021-34473 · published 14 July 2021

CVE-2021-34473: Microsoft Exchange Server SSRF Enables Remote Code Execution

Microsoft · Exchange Server

CVE-2021-34473 is a critical server-side request forgery (SSRF) flaw in Microsoft Exchange Server that leads to remote code execution. It is part of the ProxyShell exploit chain and allows an unauthenticated network attacker to execute code on the server. Because Exchange is widely deployed and the flaw is trivially reachable, it poses a severe risk to exposed mail infrastructure.

9.1 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 100% · top 0.1% CWE-918 · Server-side request forgery (SSRF)
9.1CVSS 3.1 base score, v2 10.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 1 tagged exploit
10 Aug 2026Last modified by NVD

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.1, unauthenticated network RCE, active exploitation in the wild, CISA KEV listing with ransomware use, and near-maximum EPSS score make this an urgent patching priority.

What it is

CVE-2021-34473 is a critical server-side request forgery (SSRF) flaw in Microsoft Exchange Server that leads to remote code execution. It is part of the ProxyShell exploit chain and allows an unauthenticated network attacker to execute code on the server. Because Exchange is widely deployed and the flaw is trivially reachable, it poses a severe risk to exposed mail infrastructure.

Impact

An unauthenticated attacker can execute arbitrary code on the Exchange server, gaining full control of the host and access to mail data. This can lead to data theft, lateral movement, and ransomware deployment.

Attack surface

The flaw is reachable over the network via HTTP/HTTPS on the Exchange server (AV:N, PR:N, UI:N). No authentication or user interaction is required, so any internet-exposed Exchange endpoint is a potential target.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware campaign use, and EPSS probability is 0.99999 (99.997th percentile). Public exploit code is referenced in Packet Storm and ZDI advisories, confirming active exploitation.

What to do

  • Apply the Microsoft security updates referenced in the MSRC advisory immediately.
  • If patching cannot be done at once, restrict external access to Exchange OWA/ECP endpoints and block untrusted traffic.
  • Enable and enforce multi-factor authentication on all Exchange and domain accounts.
  • Monitor for and remove web shells and suspicious files left by prior exploitation.
  • Follow CISA KEV required action and apply updates per vendor instructions by the due date.

Detection

  • Hunt for unusual HTTP requests to Exchange Autodiscover, ECP, or OWA paths that match known ProxyShell patterns.
  • Monitor for creation of suspicious .aspx files or web shells in Exchange directories.
  • Review Exchange and IIS logs for anomalous POST requests or requests with malformed URLs.
  • Alert on unexpected child processes spawned by w3wp.exe or Exchange-related services.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-34473 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Exchange Server Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-34473 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-21410Microsoft Exchange Server improper authentication privilege escalationCVE-2024-21410 is an improper authentication (CWE-287) elevation of privilege flaw in Microsoft Exchange Server. It is network-reachable with no priv…KEVEPSS 13%analysed9.1CVE-2021-26855Microsoft Exchange Server SSRF enabling remote code executionCVE-2021-26855 is a server-side request forgery (CWE-918) in Microsoft Exchange Server that is part of the ProxyLogon exploit chain and can lead to r…KEVEPSS 100%analysed9.0CVE-2021-34523Microsoft Exchange Server privilege escalation flawCVE-2021-34523 is a privilege escalation vulnerability in Microsoft Exchange Server. It is a component of the ProxyShell exploit chain, where it is u…KEVEPSS 100%analysed8.8CVE-2023-21529Microsoft Exchange Server deserialization flaw enables remote code executionCVE-2023-21529 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft Exchange Server that allows remote code execution. It carr…KEVEPSS 59%analysed8.8CVE-2022-41080Microsoft Exchange Server elevation of privilegeCVE-2022-41080 is an elevation of privilege vulnerability in Microsoft Exchange Server. A network-reachable attacker with low privileges can exploit …KEVEPSS 77%analysed8.8CVE-2022-41040Microsoft Exchange Server SSRF elevation of privilegeCVE-2022-41040 is a server-side request forgery (SSRF) flaw in Microsoft Exchange Server that allows an authenticated attacker to escalate privileges…KEVEPSS 100%analysed8.8CVE-2021-42321Microsoft Exchange Server remote code execution flawCVE-2021-42321 is a remote code execution vulnerability in Microsoft Exchange Server. It is remotely reachable over the network with low complexity, …KEVEPSS 92%analysed8.8CVE-2020-0688Microsoft Exchange Server memory corruption allows remote code executionMicrosoft Exchange Server fails to properly handle objects in memory, allowing an authenticated remote attacker to execute code on the server. The fl…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2021-34473), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.