EXPOSURES › CVE-2021-27065
CVE-2021-27065
CRITICAL ⌖ ON CISA KEV · EXPLOITEDMicrosoft Exchange Server vulnerabilities (ProxyLogon) enabled widespread remote code execution, actively exploited by ransomware groups.
A critical vulnerability in Microsoft Exchange Server, part of the ProxyLogon exploit chain, allowed for remote code execution, leading to widespread compromise and ransomware attacks. DIB organizations using vulnerable Exchange Server instances face significant exposure, potential compliance failures (CMMC DF, MP), and must immediately patch or mitigate the risk. Failure to address this promptly can result in severe data breaches and regulatory penalties.
Shame score — The widespread exploitation of a known, critical vulnerability in a widely-used enterprise product demonstrates a significant failure in Microsoft's secure development practices and resulted in substantial real-world damage.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
"Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |