Skip to main content

CVE detail

CVE-2021-34473

Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 9.1 · CriticalBuzz score 82.5KEV listed1 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 82.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 7.5
Mention score
30.0
74 evidence mentions in the snapshot
Diversity score
20.0
12 sources across 6 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
7.5
1 repos · best confidence 0.99
Best PoC traction
1253
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
74 source links · newest first
  • For years, I watched organizations treat vulnerability data like a compliance chore. It was something to scan, sort and patch against deadlines. Yet buried in those reports is a treasure map of sorts, where an attacker is likely to strike first. In my previous red team and incident responder roles, minus a credential leak or […]

    newswww.csoonline.comNov 19, 2025, 2:06 PM
  • Researchers have documented a previously unknown threat actor that aligns with China’s intelligence collection interests. The group primarily targets government and telecommunications organizations from Africa, the Middle East, and Asia with the goal of maintaining long-term covert access to critical systems. Over the past two years researchers from Palo Alto Networks have investigated separate clusters […]

    newswww.csoonline.comOct 1, 2025, 9:58 PM
  • Unknown threat actors have compromised internet-accessible Microsoft Exchange Servers of government organizations and companies around the world, and have injected the organizations’ Outlook on the Web (OWA) login page with browser-based keyloggers, Positive Technologies researchers have warned. The keylogging JavaScript code (Source: Positive Technologies) The initial vector for compromise is unknown The researchers haven’t been able to pinpoint how the attackers gained access to the compromised servers. Some of them were vulnerable to a slew … More →

    newswww.helpnetsecurity.comJun 17, 2025, 3:35 PM
  • The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have issued a joint advisory about the activities of a ransomware group from China dubbed Ghost, which has compromised organizations in over 70 countries over the past four years. The Ghost group began its activities in early 2021, but attacks have […]

    newswww.csoonline.comFeb 21, 2025, 8:23 PM
  • CISA and the FBI warn organizations of attacks employing the Ghost (Cring) ransomware, operated by Chinese hackers.

    newswww.securityweek.comFeb 20, 2025, 1:24 PM
  • A subgroup of Russia’s Sandworm APT has been working to achieve initial and persistent access to the IT networks of organizations working in economic sectors Russia is interested in. “In 2022, its primary focus was Ukraine, specifically targeting the energy, retail, education, consulting, and agriculture sectors. In 2023, it globalized the scope of its compromises, leading to persistent access within numerous sectors in the United States, Europe, Central Asia, and the Middle East,” Microsoft’s researchers … More →

    newswww.helpnetsecurity.comFeb 13, 2025, 1:25 PM
  • A subgroup of the Russia-linked Seashell Blizzard APT group (aka Sandworm) ran a global multi-year initial access operation called BadPilot. Microsoft shared findings on research on a subgroup of the Russia-linked APT group Seashell Blizzard behind the global BadPilot campaign, which compromises infrastructure to support Russian cyber operations. Seashell Blizzard (aka Sandworm, BlackEnergy and TeleBots) has been […]

    newssecurityaffairs.comFeb 13, 2025, 12:21 PM
  • A subgroup of the Russia-linked Seashell Blizzard is tasked with broad initial access operations to sustain long-term persistence.

    newswww.securityweek.comFeb 12, 2025, 5:01 PM
  • Multiple cybersecurity agencies released a joint advisory warning about a China-linked group APT40 ‘s capability to rapidly exploit disclosed security flaws. Cybersecurity agencies from Australia, Canada, Germany, Japan, New Zealand, South Korea, the U.K., and the U.S. released a joint advisory warning about the China-linked group APT40 (aka TEMP.Periscope, TEMP.Jumper, Bronze Mohawk, Gingham Typhoon, ISLANDDREAMS, Kryptonite Panda, […]

    newssecurityaffairs.comJul 10, 2024, 1:17 PM
  • Seven nations are backing Australia in calling out a China-linked hacking group for compromising government networks.

    newswww.securityweek.comJul 9, 2024, 10:43 AM
  • A Chinese APT group is targeting political entities across multiple continents. Named Operation Diplomatic Specter, this campaign uses rare techniques and a unique toolset.

    vendorunit42.paloaltonetworks.comMay 23, 2024, 10:00 AM
  • A threat actor is targeting organizations in Africa and the Middle East by exploiting Microsoft Exchange Server flaws to deliver malware. Positive Technologies researchers observed while responding to a customer’s incident spotted an unknown keylogger embedded in the main Microsoft Exchange Server page. The keylogger was used to collect account credentials. Further investigation allowed to identify over […]

    newssecurityaffairs.comMay 22, 2024, 1:19 PM
  • New CISA guidance details cyber threats and risks to healthcare and public health organizations and recommends mitigations.

    newswww.securityweek.comNov 20, 2023, 2:52 PM
  • China-linked threat actor Earth Lusca used a new Linux malware dubbed SprySOCKS in a recent cyber espionage campaign. Researchers from Trend Micro, while monitoring the activity of the China-linked threat actor Earth Lusca, discovered an encrypted file hosted on a server under the control of the group. Additional analysis led to the discovery of a […]

    newssecurityaffairs.comSep 19, 2023, 7:51 AM
  • Old vulnerabilities are still a big problemHelp Net Security

    A recently flagged phishing campaign aimed at delivering the Agent Tesla RAT to unsuspecting users takes advantage of old vulnerabilities in Microsoft Office that allow remote code execution. “Despite fixes for CVE-2017-11882/CVE-2018-0802 being released by Microsoft in November, 2017 and January, 2018, this vulnerability remains popular amongst threat actors, suggesting there are still unpatched devices in the wild, even after over five years,” says Fortinet researcher Xiaopeng Zhang. “We are observing and mitigating 3000 attacks … More →

    newswww.helpnetsecurity.comSep 6, 2023, 1:51 PM
  • Top 12 vulnerabilities routinely exploited in 2022Help Net Security

    Cybersecurity agencies from member countries of the Five Eyes intelligence alliance have released a list of the top 12 vulnerabilities routinely exploited in 2022, plus 30 additional ones also “popular” with attackers. The top 12 “In 2022, malicious cyber actors exploited older software vulnerabilities more frequently than recently disclosed vulnerabilities and targeted unpatched, internet-facing systems. Proof of concept (PoC) code was publicly available for many of the software vulnerabilities or vulnerability chains likely facilitating exploitation … More →

    newswww.helpnetsecurity.comAug 4, 2023, 1:17 PM
  • Five Eyes government agencies have published a list of the software vulnerabilities that were most frequently exploited in malicious attacks in 2022.

    newswww.securityweek.comAug 4, 2023, 9:08 AM
  • CISA, the FBI, and NSA, along with Five Eyes cybersecurity agencies published a list of the 12 most exploited vulnerabilities of 2022. CISA, the NSA, and the FBI, in collaboration with cybersecurity authorities from Australia, Canada, New Zealand, and the United Kingdom, have published a list of the 12 most exploited vulnerabilities of 2022. The […]

    newssecurityaffairs.comAug 4, 2023, 6:30 AM
  • Google’s Threat Analysis Group Google states that more than 40% of zero-day flaws discovered in 2022 were variants of previous issues. The popular Threat Analysis Group (TAG) Maddie Stone wrote Google’s fourth annual year-in-review of zero-day flaws exploited in-the-wild [2021, 2020, 2019], it is built off of the mid-year 2022 review. In 2022, the researchers […]

    newssecurityaffairs.comJul 30, 2023, 4:38 PM
  • Manic Menagerie 2.0 is a campaign deploying coin miners and web shells, among other tactics. Hijacked machines could be used as C2 for further operations.

    vendorunit42.paloaltonetworks.comJun 28, 2023, 1:00 PM
  • The Log4Shell critical vulnerability that impacted millions of enterprise applications remains a common cause for security breaches a year after it received patches and widespread attention and is expected to remain a popular target for some time to come. Its long-lasting impact highlights the major risks posed by flaws in transitive software dependencies and the […]

    newswww.csoonline.comDec 28, 2022, 10:00 AM
  • 26th December – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 26th December, please download our Threat_Intelligence Bulletin TOP ATTACKS AND BREACHES LastPass revealed that it has been breached for the second time this year, an event that resulted in attackers stealing customer encrypted password vaults and additional account information. The breach was achieved after […]

    vendorresearch.checkpoint.comDec 26, 2022, 3:09 PM
  • Last year, two high severity, easily exploitable Microsoft Exchange vulnerabilities dubbed ProxyLogon and ProxyShell made waves in the infosec sphere. Nearly a year later, Exchange Server admins are met with another threat: ProxyNotShell, which in fact is a vulnerability chain comprising two actively exploited flaws: CVE-2022-41040 is a server-side request forgery (SSRF) vulnerability that an […]

    newswww.csoonline.comDec 15, 2022, 10:00 AM
  • Hive ransomware operators have extorted over $100 million in ransom payments from over 1,300 companies worldwide as of November 2022. The threat actors behind the Hive ransomware-as-a-service (RaaS) have extorted $100 million in ransom payments from over 1,300 companies worldwide as of November 2022, reported the U.S. cybersecurity and intelligence authorities. “As of November 2022, […]

    newssecurityaffairs.comNov 18, 2022, 11:30 AM
  • The Hive ransomware gang has victimized more than 1,300 businesses, receiving over $100 million in ransom payments over the past year and a half, US government agencies say.

    newswww.securityweek.comNov 18, 2022, 10:29 AM
  • CVE-2022-41040 and CVE-2022-41082 (aka ProxyNotShell) can be used for remote code execution. Read our analysis and suggestions for how to mitigate.

    vendorunit42.paloaltonetworks.comOct 4, 2022, 11:30 PM
  • 3rd October – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 3rd October, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research identified an ongoing, mobile malware campaign that has consistently targeted Uyghurs for at least the past seven years. Attributed to the actor Scarlet Mimic, the malware campaign was disguised […]

    vendorresearch.checkpoint.comOct 3, 2022, 3:02 PM
  • A cyberespionage group, tracked as Witchetty, used steganography to hide a previously undocumented backdoor in a Windows logo. Broadcom’s Symantec Threat Hunter Team observed a threat actor, tracked as Witchetty, using steganography to hide a previously undocumented backdoor in a Windows logo. The group used the backdoor in attacks against Middle Eastern governments. The cyber […]

    newssecurityaffairs.comSep 30, 2022, 10:14 PM
  • Government agencies in the US, UK, Canada, and Australia say that threat groups associated with Iran’s Islamic Revolutionary Guard Corps (IRGC) have been engaging in data encryption and extortion operations.

    newswww.securityweek.comSep 15, 2022, 3:45 PM
  • The 2022 Unit 42 Network Threat Trends Research Report includes an analysis of the CVEs most commonly exploited in 2021 and predictions for which CVEs attackers will likely focus on in the year to come.

    vendorunit42.paloaltonetworks.comJul 21, 2022, 1:00 PM
  • 4th July – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 4th July, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Iranian steel manufacturing plants have suffered a cyberattack which reportedly forced them to halt production. The hacker group Gonjeshke Darande, which has previously attacked the Iranian railway system, assumed responsibility for the […]

    vendorresearch.checkpoint.comJul 4, 2022, 11:28 AM
  • LockBit 2.0 has so far been this year's most active ransomware gang on double-extortion leak sites. Learn about their tactics.

    vendorunit42.paloaltonetworks.comJun 9, 2022, 1:00 PM
  • Exposed version control repositories, leaked secrets in public code repositories, a subdomain vulnerable to takover, exposed Amazon S3 buckets, and Microsoft Exchange Server servers vulnerable to CVE-2021-42321 exploitation are the most common exploit paths medium to large enterprises left open for attackers in Q1 2022, according to Mandiant. Opening doors for attackers The firm has based the list on the most common issues discovered by continuously scanning the external attack surface of its customers from … More →

    newswww.helpnetsecurity.comJun 9, 2022, 11:12 AM
  • Iranian group used Bitlocker and DiskCryptor in a series of attacks targeting organizations in Israel, the US, Europe, and Australia. Researchers at Secureworks Counter Threat Unit (CTU) are investigating a series of attacks conducted by the Iran-linked COBALT MIRAGE APT group. The threat actors have been active since at least June 2020 and are linked […]

    newssecurityaffairs.comMay 13, 2022, 6:52 AM
  • Global cybersecurity authorities have published a joint advisory on the 15 Common Vulnerabilities and Exposures (CVEs) most routinely exploited by malicious cyber actors in 2021. The advisory is co-authored by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), U.S. National Security Agency (NSA), U.S. Federal Bureau of Investigation (FBI), Australian Cyber Security Centre (ACSC), Canadian […]

    newswww.csoonline.comApr 28, 2022, 10:55 AM
  • The 15 most exploited vulnerabilities in 2021Help Net Security

    In 2021, threat actors aggressively exploited newly disclosed critical software vulnerabilities to hit a broad set of targets worldwide, says the latest advisory published by the US Cybersecurity and Infrastructure Security Agency. Most exploited vulnerabilities, new and old Compiled by cybersecurity authorities from the Five Eyes intelligence alliance, the list of top 15 CVEs routinely exploited by attackers in 2021 looks like this: CVE-2021-44228 (aka Log4Shell) – in Apache Log4j CVE-2021-40539 – in Zoho ManageEngine … More →

    newswww.helpnetsecurity.comApr 28, 2022, 7:48 AM
  • 25th April – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 25th April, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Russian state-sponsored APT actor Gamaredon (aka Shuckworm) has targeted Ukrainian organizations using at least four different variants of the Pterodo backdoor, likely to maintain persistence on infected computers. The group has been […]

    vendorresearch.checkpoint.comApr 25, 2022, 2:32 PM
  • BlackByte is ransomware as a service that emerged in July 2021. Read our overview and recommended courses of action for mitigation.

    vendorunit42.paloaltonetworks.comApr 21, 2022, 7:00 PM
  • 21st February– Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 21st February, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has investigated the attack against Iranian broadcasting that occurred in late January. CPR was able to discover part of the tools that were utilized in this operation, including the […]

    vendorresearch.checkpoint.comFeb 21, 2022, 2:12 PM
  • Another gang, Night Sky ransomware operation, started exploiting the Log4Shell vulnerability in the Log4j library to gain access to VMware Horizon systems. The Night Sky ransomware operation started exploiting the Log4Shell flaw (CVE-2021-44228) in the Log4j library to gain access to VMware Horizon systems. The ransomware gang started its operations on December 27, 2021, and […]

    newssecurityaffairs.comJan 11, 2022, 2:52 PM
  • The Apache Log4j vulnerability has made global headlines since it was discovered in early December. The flaw has impacted vast numbers of organizations around the world as security teams have scrambled to mitigate the associated risks. Here is a timeline of the key events surrounding the Log4j vulnerability as they have unfolded. Thursday, December 9: […]

    newswww.csoonline.comJan 7, 2022, 10:00 AM
  • Network attacks observed August-October 2021 included high levels of cross-site scripting, code execution and directory traversal.

    vendorunit42.paloaltonetworks.comDec 21, 2021, 8:00 PM
  • The news of active exploitation of the Microsoft Exchange Server vulnerabilities has highlighted the importance of network visibility in securing critical server infrastructure. Microsoft has quickly patched vulnerabilities, but there remain important points to note. First, the general class of server-side request forgery (SSRF) attacks that were used against Microsoft Exchange Server in this case can also […]

    newswww.csoonline.comDec 14, 2021, 12:44 AM
  • Microsoft software products are a connective tissue of many organizations, from online documents (creating, sharing, storing), to email and calendaring, to the operating systems that enable business operations on the front and back ends, both in the cloud and on premises. Over 1 million companies worldwide and over 731,000 companies in the U.S. use Office 365, and though Microsoft offers no hard stats, some sources suggest there are over 90,000 Microsoft partners facilitating services and … More →

    newswww.helpnetsecurity.comDec 10, 2021, 6:30 AM
  • 6th December – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 6th December, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has identified ongoing campaigns in Iran using socially engineered SMS messages to infect tens of thousands of citizens’ devices. The SMS, impersonating Iranian government services, lures victims into downloading malicious […]

    vendorresearch.checkpoint.comDec 6, 2021, 4:29 PM
  • Threat actors are targeting IKEA employees in an internal phishing campaign leveraging stolen reply-chain emails. According to BleepingComputer, threat actors are targeting IKEA employees in phishing attacks using stolen reply-chain emails. Once compromised the mail servers, threat actors use the access to reply to the company’s internal emails in reply-chain attacks. Sending the messages from […]

    newssecurityaffairs.comNov 27, 2021, 10:41 AM
  • 22nd November – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 22nd November, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Emotet, the most popular and notorious botnet before its takedown ten months ago, is back. Emotet is currently distributed via TrickBot and already launched a worldwide email spam campaign delivering malicious documents. […]

    vendorresearch.checkpoint.comNov 22, 2021, 2:39 PM
  • A malware campaign aimed at Microsoft Exchange servers exploits ProxyShell and ProxyLogon issues and uses stolen internal reply-chain emails. A malware campaign aimed at Microsoft Exchange servers exploits ProxyShell and ProxyLogon issues and uses stolen internal reply-chain emails to avoid detection. The campaign was uncovered by TrendMicro researchers that detailed the technique used to trick […]

    newssecurityaffairs.comNov 21, 2021, 11:12 AM
  • U.S., U.K. and Australia warn that Iran-linked APT groups exploiting Fortinet and Microsoft Exchange flaws to target critical infrastructure. A joint advisory released by government agencies (the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Centre (ACSC), and the United Kingdom’s National Cyber Security Centre (NCSC)) in the U.S., U.K., and […]

    newssecurityaffairs.comNov 18, 2021, 8:55 AM
  • Iranian Threat Actors Target U.S. Critical Infrastructure, Australian Organizations

    newswww.securityweek.comNov 17, 2021, 3:55 PM
  • 8th November – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 8th November, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research warns of scammers using Google Ads to steal crypto wallets, after seeing over $500k worth of cryptocurrency stolen from victims during one weekend. Scammers are placing ads at the […]

    vendorresearch.checkpoint.comNov 8, 2021, 3:41 PM
  • A newly observed Babuk ransomware campaign is targeting ProxyShell vulnerabilities in Microsoft Exchange Server, according to security researchers at Cisco Talos.

    newswww.securityweek.comNov 5, 2021, 5:39 PM
  • New “ChamelGang” APT group group has not been associated with any existing threat actor

    newswww.securityweek.comOct 1, 2021, 2:33 PM
  • 6th September – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 6th September, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Following the SolarWinds Orion supply-chain attack, the software firm Autodesk announced they identified a compromised server and realized they were also attacked by the Russian linked group Cozy Bear as part of […]

    vendorresearch.checkpoint.comSep 5, 2021, 4:19 PM
  • In August, Orange Tsai released details and also spoke at BlackHat and DEFCON detailing his security research into Microsoft Exchange. His latest blog post details a series of vulnerabilities dubbed ProxyShell. ProxyShell is a chain of three vulnerabilities: CVE-2021-34473 – Pre-auth Path Confusion leads to ACL Bypass CVE-2021-34523 – Elevation of Privilege on Exchange PowerShell Backend CVE-2021-31207 – Post-auth Arbitrary-File-Write leads to […]

    exploithorizon3.aiSep 4, 2021, 6:46 PM
  • The Conti ransomware operators are targeting Microsoft Exchange servers leveraging recently disclosed ProxyShell vulnerability exploits. The Conti ransomware gang is targeting Microsoft Exchange servers leveraging exploits with recently disclosed ProxyShell vulnerabilities. ProxyShell is the name of three vulnerabilities that could be chained by an unauthenticated remote attacker to gain code execution on Microsoft Exchange servers. […]

    newssecurityaffairs.comSep 3, 2021, 5:00 PM
  • A new ransomware threat called LockFile has been victimizing enterprises worldwide since July. Key to its success are a few new tricks that make it harder for anti-ransomware solutions to detect it. The threat uses what researchers from antivirus vendor Sophos call “intermittent encryption,” meaning it only encrypts chunks of data inside a file instead […]

    newswww.csoonline.comAug 30, 2021, 6:36 PM
  • 30th August – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 30th August, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Karapatan, the Philippine human rights alliance, has suffered a massive and prolonged Distributed Denial of Service (DDoS) attack. The attack targeted the online solidarity campaign #StopTheKillingsPH and was allegedly conducted by the […]

    vendorresearch.checkpoint.comAug 30, 2021, 4:03 PM
  • Microsoft on Wednesday warned Exchange customers that their deployments are exposed to attacks exploiting the ProxyShell vulnerabilities , unless the adequate patches have been installed.

    newswww.securityweek.comAug 26, 2021, 11:11 AM
  • US CISA issued an urgent alert to warn admins to address ProxyShell vulnerabilities on-premises Microsoft Exchange servers. The US Cybersecurity and Infrastructure Security Agency (CISA) issued an alert to warn admins to address actively exploited ProxyShell vulnerabilities on-premises Microsoft Exchange servers. ProxyShell is the name of three vulnerabilities that could be chained by an unauthenticated […]

    newssecurityaffairs.comAug 23, 2021, 8:18 PM
  • 23rd August – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 23rd August, please download our Threat Intelligence Bulletin. Top Attacks and Breaches The Hive ransomware gang has encrypted computers of Memorial Health System, a chain that operates hospitals and clinics in the US, eventually forcing workers to operate with paper charts and cancel surgeries. […]

    vendorresearch.checkpoint.comAug 23, 2021, 6:20 PM
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) over the weekend issued an alert to warn of malicious actors actively exploiting the recently disclosed Microsoft Exchange vulnerabilities named ProxyShell.

    newswww.securityweek.comAug 23, 2021, 11:33 AM
  • Three so-called “ProxyShell” vulnerabilities are being actively exploited by various attackers to compromise Microsoft Exchange servers around the world, the Cybersecurity and Infrastructure Security Agency (CISA) warned over the weekend. The vulnerabilities The three ProxyShell vulnerabilities that can be connected in a complete exploit chain are as follows. CVE-2021-34473 – Pre-auth Path Confusion leads to ACL Bypass CVE-2021-34523 – Elevation of Privilege on Exchange PowerShell Backend CVE-2021-31207 – Post-auth Arbitrary-File-Write leads to RCE The vulnerabilities … More →

    newswww.helpnetsecurity.comAug 23, 2021, 10:55 AM
  • A new ransomware gang named LockFile targets Microsoft Exchange servers exploiting the recently disclosed ProxyShell vulnerabilities. A new ransomware gang named LockFile targets Microsoft Exchange servers using the recently disclosed ProxyShell vulnerabilities. The popular security expert Kevin Beaumont was one of the first researchers to report that the LockFile operators are using the Microsoft Exchange ProxyShell and the Windows […]

    newssecurityaffairs.comAug 21, 2021, 6:03 PM
  • 16th August – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 16th August, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has revealed that the threat actor behinds last month’s cyber-attack on Iran’s train system is “Indra”, a group that identifies itself as Iranian regime opposition. They used similar tools […]

    vendorresearch.checkpoint.comAug 16, 2021, 5:25 PM
  • Threat actors have started exploiting the recently disclosed Microsoft Exchange Server vulnerabilities to deliver web shells that give them access to the compromised system.

    newswww.securityweek.comAug 13, 2021, 10:08 AM
  • Tens of thousands of internet-exposed Microsoft Exchange servers appear to be affected by the ProxyShell vulnerabilities , and they could get compromised at any moment considering that threat actors are already scanning the web for vulnerable devices.

    newswww.securityweek.comAug 10, 2021, 10:21 AM
  • Organizations have been warned that hackers are scanning the internet for vulnerable Microsoft Exchange servers affected by a series of vulnerabilities that were disclosed by researchers last week.

    newswww.securityweek.comAug 9, 2021, 10:56 AM
  • Threat actors are actively scanning for the Microsoft Exchange ProxyShell RCE flaws after technical details were released at the Black Hat conference. Threat actors started actively scanning for the Microsoft Exchange ProxyShell remote code execution flaws after researchers released technical details at the Black Hat hacking conference. ProxyShell is the name of three vulnerabilities that could be […]

    newssecurityaffairs.comAug 9, 2021, 6:55 AM
  • No excerpt available.

    Mitigationwww.cisa.govJul 14, 2021, 6:15 PM
  • https://www.zerodayinitiative.com/advisories/ZDI-21-821/www.zerodayinitiative.com

    No excerpt available.

    Exploitwww.zerodayinitiative.comJul 14, 2021, 6:15 PM
  • No excerpt available.

    Vendor Advisoryportal.msrc.microsoft.comJul 14, 2021, 6:15 PM
  • No excerpt available.

    Exploitpacketstormsecurity.comJul 14, 2021, 6:15 PM
  • No excerpt available.

    Vendor Advisorymsrc.microsoft.comJul 14, 2021, 6:15 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.99 · max 1253 stars
  • W01fh4cker/SereinHigh confidence
    githubDiscovery source unavailable1253 starsDiscovered Jul 9, 2026, 1:19 AM

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence