KB5001779: Windows Server 2016 / 2019 Security Update (August 2021)
Three-bug chain enabling unauthenticated RCE on Exchange via the Autodiscover endpoint. Apply KB5004779 — publicly demonstrated at Black Hat 2021 and weaponised within days by ransomware actors.
Unauthenticated attackers can install persistent web shells, read all Exchange email, execute arbitrary commands as SYSTEM, and move laterally to the entire domain. ProxyShell was chained with PrintNightmare in several ransomware campaigns to achieve full domain compromise from the internet.
The Autodiscover endpoint normalises URLs incorrectly (CVE-2021-34473), allowing an unauthenticated attacker to reach Exchange PowerShell Remoting. Combined with an elevation of privilege bug (CVE-2021-34523) and a path traversal in the import/export mailbox feature (CVE-2021-31207), an attacker can write an ASPX web shell to an arbitrary path.
📧
Phishing link
🖼
Malicious file
🔓
Server compromised
Probably yes if any of these apply:
Affected OS versions
Security researcher Orange Tsai disclosed ProxyShell at Black Hat 2021 on August 5. Automated scanning for vulnerable Exchange servers began within 24 hours. By August 12, multiple ransomware groups (LockFile, Conti) were actively exploiting unpatched servers to deploy ransomware. CISA added all three CVEs to the Known Exploited Vulnerabilities catalog.
Manual download
For air-gapped servers or out-of-band deployment. Microsoft Update Catalog returns every OS-version variant of this update.
↗ Microsoft Update CatalogKB5001779Manual remediation steps
⏱ 2 hours including service restartApply the Microsoft Security Update
Microsoft has released an official security update that fixes this vulnerability.
Required KB Update
Affected Products
Fixed Build Numbers
Installation Methods
Windows Update (recommended)
Microsoft Update Catalog (manual download)
.msu installer with administrator privilegesWSUS / SCCM / Intune
Approve KB5001779 for the affected products in your update management console.
Microsoft Download Center Links
Verification
Confirm the update is installed:
Get-HotFix | Where-Object { $_.HotFixID -in @('KB5001779') }
References
Discovery Credit
Orange Tsai(@orange_8361) from DEVCORE Research Team working with Trend Micro Zero Day Initiative
No tested PowerShell script for this entry yet. We’re prioritising automation based on user demand.
| Patch ID | CVE ID | Vulnerability Name / Type | CVSS | Reference |
|---|---|---|---|---|
| KB5001779 | CVE-2021-34473 | See NVD | 9.8 | NVD ↗ |
| KB5001779 | CVE-2021-34523 | See NVD | 9.8 | NVD ↗ |
| KB5001779 | CVE-2021-31207 | See NVD | 9.8 | NVD ↗ |
Related vulnerabilities
KB5000871: Microsoft Exchange Server 2013 / 2016 / 2019 Security Update (March 2021)
Microsoft Exchange Server
CVE-2021-26855
CRITICAL8.8KB5019758: Microsoft Exchange Server 2013 / 2016 / 2019 Security Update (October 2022)
Microsoft Exchange Server
CVE-2022-41040
MEDIUM6.5KB5002741: Windows Server Security Update (July 2025)
Microsoft SharePoint
CVE-2025-49706