Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Sep 11, 2024

CVE-2021-31196

High
EPSS 3.3%CISA KEV
Microsoft/Exchange Server

Description

Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.

EPSS — Exploit Probability

3.3%

Higher than 87.1% of all CVEs

Required Action

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-31196; https://nvd.nist.gov/vuln/detail/CVE-2021-31196

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
3.3%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Aug 21, 2024

Added to KEV

Aug 21, 2024

Remediation Due

Sep 11, 2024

Affected Product

Microsoft

Exchange Server

View all Microsoft CVEs