nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-28481 CVE-2021-28481
CRITICALNuclei
Microsoft Exchange Server Remote Code Execution Vulnerability
Record summary
CVE-2021-28481 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-28480, CVE-2021-28482, CVE-2021-28483.
Description source: GitHub Advisory
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 25, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
Exchange ServerBrowse Microsoft / Exchange Server | VulnCheck | Version data not supplied | |
Microsoft Exchange Server 2013 Cumulative Update 23Browse Microsoft / Microsoft Exchange Server 2013 Cumulative Update 23 | CVE List | 15.00.0 to < 15.00.1497.015 | affected |
Microsoft Exchange Server 2016 Cumulative Update 19Browse Microsoft / Microsoft Exchange Server 2016 Cumulative Update 19 | CVE List | 15.01.0 to < 15.01.2176.012 | affected |
Microsoft Exchange Server 2016 Cumulative Update 20Browse Microsoft / Microsoft Exchange Server 2016 Cumulative Update 20 | CVE List | 15.01.0 to < 15.01.2242.008 | affected |
Microsoft Exchange Server 2019 Cumulative Update 8Browse Microsoft / Microsoft Exchange Server 2019 Cumulative Update 8 | CVE List | 15.02.0 to < 15.02.0792.013 | affected |
Microsoft Exchange Server 2019 Cumulative Update 9Browse Microsoft / Microsoft Exchange Server 2019 Cumulative Update 9 | CVE List | 15.02.0 to < 15.02.0858.010 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALMicrosoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)CVSS 9.8
Microsoft Exchange Server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server.
Impact
Attackers can execute arbitrary code remotely, potentially leading to full system compromise or data breach
Remediation
Apply the latest security patches and updates provided by Microsoft for Exchange Server
Authorsdaffainfo
Template tagscvecve2021ssrfrceexchangemicrosoftvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_20:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_9:*:*:*:*:*:*
Shodan: http.favicon.hash:1768726119
Shodan: http.title:"outlook"
Shodan: cpe:"cpe:2.3:a:microsoft:exchange_server"
FOFA: title="outlook"
FOFA: icon_hash=1768726119
Google: intitle:"outlook"
https://sec.vnpt.vn/2021/04/microsoft-exchange-from-deserialization-to-post-auth-rce-cve-2021-28482 https://hitcon.org/2021/agenda/279d7810-e619-4dc3-9113-b11bad5277ec/The%20Proxy%20Era%20of%20Microsoft%20Exchange%20Server.pdf https://www.youtube.com/watch?v=vn4niT9XEIM https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-28481 https://nvd.nist.gov/vuln/detail/cve-2021-28481
Source: ProjectDiscovery
References
2portal.msrc.microsoft.com
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-28481