CVE-2021-31196
Microsoft Exchange Server Information Disclosure Vulnerability
CVSS
7.2
High
EPSS
54.1%
p99
KEV
YES
Aug 21, 2024
Exploit Today
80
0-100
Published: Jul 14, 2021 · Last modified: Aug 10, 2026
Product
Microsoft / Exchange Server
Vulnerability
Microsoft Exchange Server Information Disclosure Vulnerability
Added to KEV
Aug 21, 2024
Remediate by
Sep 11, 2024
Known ransomware use
No
Summary description
Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-31196; https://nvd.nist.gov/vuln/detail/CVE-2021-31196
Microsoft Exchange Server Remote Code Execution Vulnerability