← Vulnerability feed

Vulnerability record · CVE-2021-34523 · published 14 July 2021

CVE-2021-34523: Microsoft Exchange Server privilege escalation flaw

Microsoft · Exchange Server

CVE-2021-34523 is a privilege escalation vulnerability in Microsoft Exchange Server. It is a component of the ProxyShell exploit chain, where it is used after initial access to gain higher privileges on the server. Because it is chained with remote code execution flaws, it materially raises the impact of an Exchange compromise.

9.0 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 100% · top 0.1%
9.0CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 1 tagged exploit
10 Aug 2026Last modified by NVD

Description

Microsoft Exchange Server Elevation of Privilege Vulnerability

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: medium.

critical priorityIt is a critical-severity flaw in a widely deployed mail server, listed in KEV with known ransomware use and near-maximum EPSS, and it is part of an actively exploited chain.

What it is

CVE-2021-34523 is a privilege escalation vulnerability in Microsoft Exchange Server. It is a component of the ProxyShell exploit chain, where it is used after initial access to gain higher privileges on the server. Because it is chained with remote code execution flaws, it materially raises the impact of an Exchange compromise.

Impact

An attacker who already has a foothold on the Exchange server can elevate privileges, enabling further control of the host and its mail data. In the ProxyShell chain it serves as the step that turns limited access into administrative-level control.

Attack surface

The CVSS vector is local (AV:L) with no privileges or user interaction required, so it is reached by an attacker who can already execute code or interact with the Exchange service locally. It is not a standalone remote entry point; it depends on prior access obtained through other flaws.

Exploitation

Listed in CISA KEV with a 2021 due date and flagged for known ransomware campaign use, and EPSS is near 1.0 (99.99th percentile). Public exploit code exists via the Packet Storm ProxyShell reference, confirming active exploitation in the wild.

What to do

  • Apply the Microsoft Exchange Server security updates referenced in the MSRC advisory immediately.
  • Treat any unpatched, internet-facing Exchange server as compromised and investigate for ProxyShell exploitation.
  • Restrict and monitor external access to Exchange endpoints such as Autodiscover and PowerShell virtual directories.
  • Ensure Exchange servers run with least privilege and segment them from other critical systems.
  • Verify patch level against the vendor advisory rather than relying on version strings alone.

Detection

  • Hunt for suspicious w3wp.exe child processes and unusual PowerShell spawned by Exchange worker processes.
  • Review Exchange and IIS logs for anomalous requests to Autodiscover and PowerShell endpoints consistent with ProxyShell activity.
  • Monitor for creation of unexpected mailboxes, new admin roles, or web shells dropped in Exchange directories.
  • Correlate local privilege escalation events on Exchange hosts with prior external request activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-34523 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Exchange Server Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-34523 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-21410Microsoft Exchange Server improper authentication privilege escalationCVE-2024-21410 is an improper authentication (CWE-287) elevation of privilege flaw in Microsoft Exchange Server. It is network-reachable with no priv…KEVEPSS 13%analysed9.1CVE-2021-34473Microsoft Exchange Server SSRF Enables Remote Code ExecutionCVE-2021-34473 is a critical server-side request forgery (SSRF) flaw in Microsoft Exchange Server that leads to remote code execution. It is part of …KEVEPSS 100%analysed9.1CVE-2021-26855Microsoft Exchange Server SSRF enabling remote code executionCVE-2021-26855 is a server-side request forgery (CWE-918) in Microsoft Exchange Server that is part of the ProxyLogon exploit chain and can lead to r…KEVEPSS 100%analysed8.8CVE-2023-21529Microsoft Exchange Server deserialization flaw enables remote code executionCVE-2023-21529 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft Exchange Server that allows remote code execution. It carr…KEVEPSS 59%analysed8.8CVE-2022-41080Microsoft Exchange Server elevation of privilegeCVE-2022-41080 is an elevation of privilege vulnerability in Microsoft Exchange Server. A network-reachable attacker with low privileges can exploit …KEVEPSS 77%analysed8.8CVE-2022-41040Microsoft Exchange Server SSRF elevation of privilegeCVE-2022-41040 is a server-side request forgery (SSRF) flaw in Microsoft Exchange Server that allows an authenticated attacker to escalate privileges…KEVEPSS 100%analysed8.8CVE-2021-42321Microsoft Exchange Server remote code execution flawCVE-2021-42321 is a remote code execution vulnerability in Microsoft Exchange Server. It is remotely reachable over the network with low complexity, …KEVEPSS 92%analysed8.8CVE-2020-0688Microsoft Exchange Server memory corruption allows remote code executionMicrosoft Exchange Server fails to properly handle objects in memory, allowing an authenticated remote attacker to execute code on the server. The fl…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2021-34523), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.