August 21, 2024 · Applied Cybernetics Group
CVE-2021-31196 — Microsoft Exchange Server
Microsoft Exchange Server Information Disclosure Vulnerability
- Added to KEV
2024-08-21- Federal due date
2024-09-11- Vendor
- Microsoft
- Product
- Exchange Server
- EPSS
- 87.5th percentile (score 0.033, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2021-31196
CISA short description
Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.