Vulnerability record · CVE-2021-34473 · published 14 July 2021
CVE-2021-34473: Microsoft Exchange Server SSRF Enables Remote Code Execution
Microsoft · Exchange Server
CVE-2021-34473 is a critical server-side request forgery (SSRF) flaw in Microsoft Exchange Server that leads to remote code execution. It is part of the ProxyShell exploit chain and allows an unauthenticated network attacker to execute code on the server. Because Exchange is widely deployed and the flaw is trivially reachable, it poses a severe risk to exposed mail infrastructure.
Description
Microsoft Exchange Server Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Automated analysis
critical priorityCVSS 9.1, unauthenticated network RCE, active exploitation in the wild, CISA KEV listing with ransomware use, and near-maximum EPSS score make this an urgent patching priority.
What it is
CVE-2021-34473 is a critical server-side request forgery (SSRF) flaw in Microsoft Exchange Server that leads to remote code execution. It is part of the ProxyShell exploit chain and allows an unauthenticated network attacker to execute code on the server. Because Exchange is widely deployed and the flaw is trivially reachable, it poses a severe risk to exposed mail infrastructure.
Impact
An unauthenticated attacker can execute arbitrary code on the Exchange server, gaining full control of the host and access to mail data. This can lead to data theft, lateral movement, and ransomware deployment.
Attack surface
The flaw is reachable over the network via HTTP/HTTPS on the Exchange server (AV:N, PR:N, UI:N). No authentication or user interaction is required, so any internet-exposed Exchange endpoint is a potential target.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware campaign use, and EPSS probability is 0.99999 (99.997th percentile). Public exploit code is referenced in Packet Storm and ZDI advisories, confirming active exploitation.
What to do
- Apply the Microsoft security updates referenced in the MSRC advisory immediately.
- If patching cannot be done at once, restrict external access to Exchange OWA/ECP endpoints and block untrusted traffic.
- Enable and enforce multi-factor authentication on all Exchange and domain accounts.
- Monitor for and remove web shells and suspicious files left by prior exploitation.
- Follow CISA KEV required action and apply updates per vendor instructions by the due date.
Detection
- Hunt for unusual HTTP requests to Exchange Autodiscover, ECP, or OWA paths that match known ProxyShell patterns.
- Monitor for creation of suspicious .aspx files or web shells in Exchange directories.
- Review Exchange and IIS logs for anomalous POST requests or requests with malformed URLs.
- Alert on unexpected child processes spawned by w3wp.exe or Exchange-related services.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-34473 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Exchange Server Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34473 | PatchVendor Advisory |
| http://packetstormsecurity.com/files/163895/Microsoft-Exchange-ProxyShell-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34473 | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-821/ | Third Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-34473 | US Government Resource |
Track CVE-2021-34473 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-34473), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.