Skip to content
COOEY

FAIL › dossier

Exchange Server

PRODUCT

· dossier confidence 60%

Microsoft Exchange Server has suffered multiple critical remote code execution vulnerabilities, including ProxyLogon and ProxyNotShell exploit chains, stemming from systemic issues in validation and deserialization logic. The company has released security updates for affected versions, but older versions like Exchange 2019 are no longer receiving public security updates.

PROFILE
CategoryEnterprise SoftwareWhat they doMicrosoft develops and supports software, services, devices, and solutions worldwide, including Exchange Server for email and collaboration.SizeLargeOwnershippublic Websitehttps://www.microsoft.com ↗
SECURITY POSTURE

Microsoft has a history of critical remote code execution vulnerabilities in Exchange Server, including ProxyLogon and ProxyNotShell chains, indicating systemic issues in validation and deserialization logic.

Notable failures
  • CVE-2022-41080 RCE
  • CVE-2022-41040 ProxyNotShell RCE
  • CVE-2021-26857 ProxyLogon RCE
  • CVE-2021-34473 RCE0day
  • CVE-2021-26855 RCE0day
  • CVE-2021-27065 RCE
Patterns: repeated unpatched edge-device RCEs; chainable vulnerabilities enabling privilege escalation; deserialization of untrusted data leading to RCE
FAILURE HISTORY · 17
DATEEVENTSEVSUMMARY
2024-02-15 CVE-2024-21410 high Microsoft Exchange Server is actively exploited via CVE-2024-21410, enabling privilege escalation and ransomware entry.
2023-01-10 CVE-2022-41080 critical Microsoft Exchange Server privilege escalation vulnerability (CVE-2022-41080) chainable with RCE CVE-2022-41082 enables full system compromise.
2022-09-30 CVE-2022-41082 critical Microsoft Exchange Server's ProxyNotShell vulnerability allowed authenticated remote code execution, enabling ransomware attacks when chained with CVE-2022-41040.
2022-09-30 CVE-2022-41040 critical Microsoft Exchange Server's ProxyNotShell SSRF vulnerability, when chained with CVE-2022-41082, enables remote code execution and was actively exploited in the wild for ransomware attacks.
2021-11-03 CVE-2020-17144 high Microsoft Exchange Server's CVE-2020-17144 allowed remote code execution via improper cmdlet argument validation, exploited in the wild starting January 2021.
2022-03-03 CVE-2018-8581 critical Microsoft Exchange Server vulnerabilities allowed attackers to impersonate users, linked to ransomware activity and actively exploited in the wild.
2022-01-18 CVE-2021-33766 high An unauthenticated attacker could steal email traffic from Microsoft Exchange Server via CVE-2021-33766, a vulnerability actively exploited in the wild.
2021-11-03 CVE-2021-26857 critical CVE-2021-26857: Microsoft Exchange Server RCE exploited in wild
2021-11-03 CVE-2020-0688 critical Microsoft Exchange Server's failure to generate unique keys allowed for remote code execution, exploited in the wild and linked to ransomware activity.
2021-11-03 CVE-2021-26858 critical Microsoft Exchange Server vulnerabilities allowed attackers to execute code remotely, often as part of ransomware attacks.
2021-11-03 CVE-2021-27065 critical Microsoft Exchange Server vulnerabilities (ProxyLogon) enabled widespread remote code execution, actively exploited by ransomware groups.
2021-11-03 CVE-2021-34523 critical A Microsoft Exchange Server vulnerability allowed privilege escalation and was actively exploited in ransomware attacks.
2021-11-03 CVE-2021-34473 critical Microsoft Exchange Server vulnerabilities allowed attackers to execute code remotely, often linked to ransomware attacks.
2021-11-03 CVE-2021-31207 critical Microsoft Exchange Server vulnerabilities allowed attackers to bypass security features and potentially deploy ransomware, impacting DIB organizations reliant on email infrastructure.
2021-11-03 CVE-2021-26855 critical Microsoft Exchange Server vulnerabilities (ProxyLogon) enabled widespread remote code execution, actively exploited by ransomware groups.
2026-04-13 CVE-2023-21529 critical Microsoft Exchange Server allows authenticated attackers to execute remote code via deserialization of untrusted data.
2024-08-21 CVE-2021-31196 high Microsoft Exchange Server is actively exploited via CVE-2021-31196, enabling remote code execution on unpatched systems.
Open questions: Exact founding year of Microsoft · Exact headquarters location · Exact company size in terms of employee count
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-16 04:35:57.352694+00:00