CISA Known Exploited Vulnerability

CVE-2021-31196

Microsoft · Exchange Server

Microsoft Exchange Server Information Disclosure Vulnerability

Date added
BOD 22-01 due date
CWE
Ransomware Unknown

CISA description

Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.

Required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.