{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2021-34473",
  "revision": 1,
  "title": "Microsoft Exchange Server — ProxyShell Remote Code Execution",
  "summary": "A request-forwarding flaw in Microsoft Exchange Server lets an unauthenticated attacker reach internal services and run code on the mail server. It is the entry point of the exploit chain published as ProxyShell.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.99999,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2021-11-03",
    "prerequisites": "Network access to an unpatched on-premises Exchange Server. No credentials needed."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Apply Microsoft's Exchange security update per the advisory; then hunt the Exchange virtual directories for web shells and rotate credentials held on that server.",
  "confidence": "medium",
  "provenance": [
    {
      "fields": [
        "title",
        "summary",
        "cvss",
        "severity",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "remediation.patch_available",
        "references"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2021-34473",
      "retrieved_at": "2026-08-07T07:53:55.549Z",
      "confidence": "medium",
      "extractor": "claude-code"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.prerequisites",
        "recommended_action"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-08-07T07:53:55.549Z",
      "confidence": "high",
      "extractor": "claude-code"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2021-34473",
      "retrieved_at": "2026-08-07T07:53:55.549Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-34473",
      "label": "NVD record"
    },
    {
      "type": "vendor_advisory",
      "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34473",
      "label": "Microsoft security update guide"
    },
    {
      "type": "exploit",
      "url": "http://packetstormsecurity.com/files/163895/Microsoft-Exchange-ProxyShell-Remote-Code-Execution.html",
      "label": "Public ProxyShell exploit"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-34473",
      "label": "CISA Known Exploited Vulnerabilities entry"
    }
  ],
  "published_at": "2021-07-14T18:15:11.163Z",
  "issued_at": "2026-08-07T07:53:55.549Z",
  "tags": [
    "microsoft",
    "exchange",
    "proxyshell",
    "mail-server",
    "kev",
    "ransomware"
  ]
}
