Cyber Resilience

CVE-2021-34523

Microsoft Exchange Server 2013 … 2019

CISA KEVActive ExploitationEUVD ExploitedPublic PoCRansomware-linked
Published
14 July 2021
Modified
10 August 2026
KEV Added
03 November 2021
Patch / advisory
CVSS Score v3.1 9.0
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
EPSS Score 0.99 100.0th percentile
Risk Priority 89 floored blend · peak EPSS

Summary

CVE-2021-34523 is a critical-severity an unspecified weakness vulnerability in Microsoft Exchange Server. Its CVSS base score is 9.0 (Critical).

Operationally, ranked in the top 0.0% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog; a public proof-of-concept is referenced.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2021-34523 is an elevation of privilege vulnerability affecting Microsoft Exchange Server. It carries a CVSS 3.1 base score of 9.0 under the vector AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N and is listed without an associated CWE.

An attacker with local access and no prior privileges or user interaction can exploit the flaw to obtain high-impact effects on confidentiality and integrity, with the impact extending across a security boundary due to the changed scope.

Public references link the issue to Microsoft Security Response Center guidance and Zero Day Initiative advisory ZDI-21-822, along with proof-of-concept material describing its role in ProxyShell remote code execution chains against Exchange deployments.

EU & UK References

Vulnerability Data

Microsoft Exchange Server Elevation of Privilege Vulnerability

CWE(s)
KEV Date Added
03 November 2021

Related Threats

CVEs Like This One

CVE-2021-26855Same product: Microsoft Exchange Serverboth on KEV
CVE-2022-41040Same product: Microsoft Exchange Serverboth on KEV
CVE-2021-26858Same product: Microsoft Exchange Serverboth on KEV
CVE-2021-42321Same product: Microsoft Exchange Serverboth on KEV
CVE-2022-41080Same product: Microsoft Exchange Serverboth on KEV
CVE-2020-17144Same product: Microsoft Exchange Serverboth on KEV
CVE-2018-8581Same product: Microsoft Exchange Serverboth on KEV
CVE-2020-0688Same product: Microsoft Exchange Serverboth on KEV
CVE-2021-31196Same product: Microsoft Exchange Serverboth on KEV
CVE-2021-27065Same product: Microsoft Exchange Serverboth on KEV

Affected Assets

microsoft
exchange server
2013, 2016, 2019

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References