Vulnerability record · CVE-2021-34523 · published 14 July 2021
CVE-2021-34523: Microsoft Exchange Server privilege escalation flaw
Microsoft · Exchange Server
CVE-2021-34523 is a privilege escalation vulnerability in Microsoft Exchange Server. It is a component of the ProxyShell exploit chain, where it is used after initial access to gain higher privileges on the server. Because it is chained with remote code execution flaws, it materially raises the impact of an Exchange compromise.
Description
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Automated analysis
critical priorityIt is a critical-severity flaw in a widely deployed mail server, listed in KEV with known ransomware use and near-maximum EPSS, and it is part of an actively exploited chain.
What it is
CVE-2021-34523 is a privilege escalation vulnerability in Microsoft Exchange Server. It is a component of the ProxyShell exploit chain, where it is used after initial access to gain higher privileges on the server. Because it is chained with remote code execution flaws, it materially raises the impact of an Exchange compromise.
Impact
An attacker who already has a foothold on the Exchange server can elevate privileges, enabling further control of the host and its mail data. In the ProxyShell chain it serves as the step that turns limited access into administrative-level control.
Attack surface
The CVSS vector is local (AV:L) with no privileges or user interaction required, so it is reached by an attacker who can already execute code or interact with the Exchange service locally. It is not a standalone remote entry point; it depends on prior access obtained through other flaws.
Exploitation
Listed in CISA KEV with a 2021 due date and flagged for known ransomware campaign use, and EPSS is near 1.0 (99.99th percentile). Public exploit code exists via the Packet Storm ProxyShell reference, confirming active exploitation in the wild.
What to do
- Apply the Microsoft Exchange Server security updates referenced in the MSRC advisory immediately.
- Treat any unpatched, internet-facing Exchange server as compromised and investigate for ProxyShell exploitation.
- Restrict and monitor external access to Exchange endpoints such as Autodiscover and PowerShell virtual directories.
- Ensure Exchange servers run with least privilege and segment them from other critical systems.
- Verify patch level against the vendor advisory rather than relying on version strings alone.
Detection
- Hunt for suspicious w3wp.exe child processes and unusual PowerShell spawned by Exchange worker processes.
- Review Exchange and IIS logs for anomalous requests to Autodiscover and PowerShell endpoints consistent with ProxyShell activity.
- Monitor for creation of unexpected mailboxes, new admin roles, or web shells dropped in Exchange directories.
- Correlate local privilege escalation events on Exchange hosts with prior external request activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-34523 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Exchange Server Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34523 | PatchVendor Advisory |
| http://packetstormsecurity.com/files/163895/Microsoft-Exchange-ProxyShell-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34523 | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-822/ | Third Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-34523 | US Government Resource |
Track CVE-2021-34523 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-34523), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.