CVE-2021-27065
KEV RANSOMWAREHIGH 7.8EPSS 99.9%
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 99.88% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03, used in ransomware campaigns
- Published
- 2021-03-02
- Updated
- 2026-08-19
Proof-of-concept exploits (17)
- http://packetstormsecurity.com/files/161938/Microsoft-Exchange-ProxyLogon-Remote-Code-Exe…
- http://packetstormsecurity.com/files/162736/Microsoft-Exchange-ProxyLogon-Collector.html
- Ahsanzia/Exchange-Exploit5★ · 2021-03-05
- Nick-Yin12/1063625220★ · 2021-04-19
- R0XDEADBEEF/CVE-2021-2685512★ · 2024-01-01
- adamrpostjr/cve-2021-2706511★ · 2021-03-09
- evilashz/ExchangeSSRFtoRCEExploit28★ · 2021-03-15
- herwonowr/exprolog186★ · 2021-10-19
- hictf/CVE-2021-26855-CVE-2021-270650★ · 2021-03-23
- kh4sh3i/ProxyLogon9★ · 2023-03-28
- p0wershe11/ProxyLogon124★ · 2021-03-17
- praetorian-inc/proxylogon-exploit52★ · 2021-03-24
- r0xDB/CVE-2021-2685512★ · 2024-01-01
- raheel0x01/CVE-2021-2685512★ · 2024-01-01
- srvaccount/CVE-2021-26855-PoC17★ · 2021-03-09
- trymonoly/ProxyLogon1★ · 2024-10-09
- zainimran/Capstone-MISP-Module1★ · 2021-05-11