LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-27065: Microsoft Exchange Server Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-27065 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

CVE-2021-27065 is a remote code execution vulnerability in Microsoft Exchange Server. It forms part of the ProxyLogon exploit chain and can let an attacker run code on the server. Public reporting and CISA note that it has been used in ransomware activity, so unpatched Exchange instances remain a high-priority risk for mail infrastructure and the data it holds.

Defenders should treat any internet-facing or internally reachable Exchange deployment as in scope until they confirm the vendor’s fixed builds are installed. Specifics on exact builds and attack prerequisites must be taken from Microsoft’s advisory rather than secondary summaries.

How it works

The weakness is recorded as CWE-39. In practical terms this class of flaw lets an attacker influence path handling so that crafted input reaches a sensitive file-system or request-processing path the application did not intend to expose. When chained with the other ProxyLogon components, the result is remote code execution on the Exchange server itself.

An attacker who can reach the vulnerable endpoint sends specially formed requests that abuse the path-handling defect. Successful abuse yields the ability to write or execute code in the context of the Exchange process. The CISA summary describes the vulnerability as unspecified beyond remote code execution and its membership in the ProxyLogon chain; therefore operators should not rely on incomplete public technical write-ups and should instead validate behavior and indicators against the official vendor advisory.

Am I affected? How to find it in your systems

Microsoft Exchange Server commonly runs on Windows Server hosts that provide corporate email, calendaring and related services. It may be deployed on-premises, in hybrid configurations, or as part of larger messaging farms. Inventory every server that hosts the Exchange role, including edge, mailbox and client-access functions.

If version or configuration data is unclear, treat the host as potentially vulnerable until the vendor advisory confirms otherwise.

How to remediate

Apply the security updates Microsoft released for this CVE exactly as directed in the vendor advisory. CISA’s required action is simply to apply those updates per vendor instructions. After patching, reboot if required and verify the new build numbers.

If you can't patch immediately

When immediate patching is impossible, reduce exposure with layered compensating controls while the update is scheduled.

These measures buy time but do not replace the vendor update.

If your data may have been exposed

Actively exploited remote-code-execution flaws on mail servers frequently lead to data theft, persistence and ransomware. If exploitation is suspected, isolate the host, preserve volatile evidence, and begin incident-response procedures including credential resets and mail-flow review. Organizations and individuals can also run a free exposure scan of their email addresses against known breach data sets to determine whether related accounts have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Exchange Server
WeaknessCWE-39
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities