← KEV catalog
CISA known exploited vulnerability

CVE-2021-31196

Microsoft Exchange Server Information Disclosure Vulnerability

SOURCE FACT

Microsoft · Exchange Server

Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.

Required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA notes

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-31196; https://nvd.nist.gov/vuln/detail/CVE-2021-31196

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?