CVE-2021-27065 Details
Description
Microsoft Exchange Server Remote Code Execution Vulnerability
A remote code execution vulnerability exists in Microsoft Exchange Server as part of the ProxyLogon exploit chain. This vulnerability allows an authenticated attacker to execute arbitrary code on the server. It affects Microsoft Exchange Server 2013, 2016, and 2019, with specific vulnerable versions within these releases.
Users can apply the security update for Microsoft Exchange Server 2013 Cumulative Update 21, Exchange Server 2016 Cumulative Update 19, or Exchange Server 2019 Cumulative Update 8. Instructions for downloading these security updates are available on the Microsoft Update Catalog.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 1, 2021References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27065 | CISA-ADP | US Government Resource |
| http://packetstormsecurity.com/files/161938/Microsoft-Exchange-ProxyLogon-Remote-Code-Execution.html | CVE | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/162736/Microsoft-Exchange-ProxyLogon-Collector.html | CVE | ExploitThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-27065 | CVE | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-27065 | [email protected] | PatchVendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Microsoft Exchange Server Remote Code Execution Vulnerability | Nov 3, 2021 | May 3, 2022 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| microsoft exchange server | 2013 cumulative_update_21 2013 cumulative_update_22 2013 cumulative_update_23 2013 sp1 2016 cumulative_update_10 2016 cumulative_update_11 2016 cumulative_update_12 2016 cumulative_update_13 2016 cumulative_update_14 2016 cumulative_update_15 2016 cumulative_update_16 2016 cumulative_update_17 2016 cumulative_update_18 2016 cumulative_update_19 2016 cumulative_update_8 2019 - 2019 cumulative_update_1 2019 cumulative_update_2 2019 cumulative_update_3 2019 cumulative_update_4 2019 cumulative_update_5 2019 cumulative_update_6 2019 cumulative_update_7 2019 cumulative_update_8 |
CPE
Remediation
| |
Change History
21 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 19, 2026 | Modified Analysis | [email protected] |
| Aug 19, 2026 | CVE Modified | [email protected] |
| Aug 12, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 30, 2025 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Mar 7, 2025 | Modified Analysis | [email protected] |
| Feb 4, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| Jul 25, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 29, 2023 | CVE Modified | [email protected] |
| Jul 12, 2022 | CWE Remap | [email protected] |
| May 23, 2022 | Modified Analysis | [email protected] |
| May 21, 2021 | CVE Modified | [email protected] |
| Mar 26, 2021 | Modified Analysis | [email protected] |
| Mar 23, 2021 | CVE Modified | [email protected] |
| Mar 8, 2021 | Initial Analysis | [email protected] |