CVE-2021-31196: Microsoft Exchange Server Information Disclosure Vulnerability
Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.
Other sources
Microsoft Exchange Server Remote Code Execution Vulnerability
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.0922.013Patch KB5004780 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2308.014Patch KB5004779 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2242.012Patch KB5004779 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.0858.015Patch KB5004780 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.00.1497.023Patch KB5004778 - Compensating control
Discontinue use of Microsoft Exchange Server if vendor mitigations are unavailable.
Event History
Frequently Asked Questions
What is CVE-2021-31196?
CVE-2021-31196 is a remote code execution vulnerability in Microsoft Exchange Server.
What is the severity of CVE-2021-31196?
The severity of CVE-2021-31196 is high with a severity value of 7.2.
Which versions of Microsoft Exchange Server are affected by CVE-2021-31196?
Microsoft Exchange Server 2013 Cumulative Update 23, 2016 Cumulative Update 20 and 21, and 2019 Cumulative Update 9 and 10 are affected by CVE-2021-31196.
How can I fix the CVE-2021-31196 vulnerability?
To fix the CVE-2021-31196 vulnerability, apply the latest security updates provided by Microsoft for the affected versions of Microsoft Exchange Server.
Where can I find more information about CVE-2021-31196?
You can find more information about CVE-2021-31196 in the Microsoft Security Guidance Advisory for CVE-2021-31196.