Microsoft Exchange Server was found to contain CVE-2021-34473, a critical flaw in the Autodiscover service that allows server-side request forgery (SSRF) and authentication bypass against Exchange Server 2013, 2016, and 2019 on x64 systems. According to Zero Day Initiative, the bug stems from improper URI validation before the service accesses resources, enabling remote, unauthenticated exploitation. Microsoft issued security updates for the vulnerability, while the CVE record assigns it a CVSS v3.1 score of 9.1 and ZDI rated the issue 10.0.
Although the flaw can be described as an SSRF and auth bypass on its own, advisories note it can be chained with additional Exchange vulnerabilities to achieve arbitrary code execution as SYSTEM, placing it in the exploitation context widely associated with ProxyShell. The issue was reported to Microsoft by orangetw, later disclosed through coordinated advisories from Microsoft and ZDI, and remains a high-priority patching concern because it can be exploited remotely without authentication on exposed Exchange deployments.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository published an Exchange_SSRF_Attacks.py tool and exploitation guide showing how to abuse Exchange autodiscover and EWS SSRF behavior to enumerate valid email accounts, search contacts and emails, and download mailbox contents including attachments. The material provided example HTTP requests and command-line usage for these attacks.
The CVE record for CVE-2021-34473 was published, identifying a critical Microsoft Exchange Server vulnerability and linking it to Microsoft's advisory.
The Microsoft Exchange Server Autodiscover SSRF/authentication bypass vulnerability tracked as CVE-2021-34473 was reported to Microsoft, with orangetw credited for the discovery/report.
The CVE record for CVE-2021-34473 was updated in the CVE database.
Zero Day Initiative published advisory ZDI-21-821 in a coordinated public release for CVE-2021-34473, describing the flaw as an Exchange Autodiscover SSRF/authentication bypass that could be chained for SYSTEM-level code execution. The advisory also stated that Microsoft had released an update to address the issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcegithub.com
Open sourcezerodayinitiative.com
Open sourceportal.msrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.