CVE-2021-34473
CRITICAL KEV RANSOMWARE NUCLEIMicrosoft Exchange ProxyShell RCE
Title source: metasploitExploitation Summary
CVE-2021-34473 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021, with confirmed use in ransomware campaigns.
EIP tracks 15 public exploits from researchers including horizon3ai, cyberheartmi9, kh4sh3i, including a Metasploit module exploits/windows/http/exchange_proxyshell_rce.
A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a functional exploit for the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) affecting Microsoft Exchange Server. The exploit automates the attack chain, including email enumeration, LegacyDN discovery, and remote code execution via PowerShell remoting.
Description
Microsoft Exchange Server Remote Code Execution Vulnerability
Exploits (15)
This repository contains a functional exploit for the ProxyShell vulnerability chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) affecting Microsoft Exchange Server. The exploit automates the attack chain, including email enumeration, LegacyDN discovery, and remote code execution via PowerShell remoting.
The repository contains a scanner for detecting the Proxyshell vulnerability (CVE-2021-34473) in Microsoft Exchange Server. It includes a Python script and a Nuclei template to check for the presence of the vulnerability by sending a crafted HTTP request and checking for specific response headers.
This repository contains a functional exploit for CVE-2021-34473, part of the ProxyShell vulnerability chain affecting Microsoft Exchange Server. The exploit leverages authentication bypass and arbitrary file write vulnerabilities to achieve remote code execution (RCE).
This repository contains a functional exploit for CVE-2021-34473, a vulnerability in Microsoft Exchange Server. The exploit leverages the ProxyShell attack chain to achieve remote code execution (RCE) by abusing the autodiscover endpoint and PowerShell remoting.
This repository contains functional exploit code for CVE-2021-34473, a vulnerability in Microsoft Exchange Server (ProxyShell). The exploit leverages authentication bypass and arbitrary file write to deliver a webshell via crafted email attachments.
This repository provides a scanner for detecting CVE-2021-34473, a Microsoft Exchange vulnerability. It includes batch scripts for single and mass scanning but does not contain exploit code.
This repository provides an Nmap script to scan for CVE-2021-34473, a vulnerability in Microsoft Exchange Server. It does not include exploit code but offers a detection mechanism via NSE script.
This repository contains a functional exploit for CVE-2021-34473 (ProxyShell), which chains multiple vulnerabilities to achieve remote code execution on Microsoft Exchange servers. The exploit leverages Autodiscover endpoint manipulation, SID leakage, and token forgery to deploy a webshell.
This repository contains functional exploit code for CVE-2021-34473, a remote code execution vulnerability in Microsoft Exchange Server. The provided scripts encode a malicious payload to bypass security mechanisms and achieve RCE via a crafted HTTP request.
This Metasploit module exploits CVE-2021-34473, part of the ProxyShell vulnerability chain, to achieve remote code execution on Microsoft Exchange Server by bypassing authentication, impersonating a user, and writing arbitrary files.
This repository contains a scanner for CVE-2021-34473 (ProxyShell) that checks for vulnerable Microsoft Exchange servers by sending a crafted HTTP request to the autodiscover endpoint and analyzing the response for specific indicators of vulnerability.
This repository contains a functional exploit for ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), a chain of vulnerabilities in Microsoft Exchange Server. The exploit merges two existing PoCs to achieve remote code execution (RCE) by leveraging authentication bypass and arbitrary file write vulnerabilities.
This repository contains a functional exploit for CVE-2021-34473 (ProxyShell), which is a remote code execution vulnerability in Microsoft Exchange Server. The exploit automates the attack chain, including authentication bypass, arbitrary file write, and remote command execution as SYSTEM.
This repository contains functional exploit code for CVE-2021-34473 (ProxyShell), demonstrating remote code execution (RCE) on Microsoft Exchange Server. The scripts include enumeration, authentication bypass, and RCE capabilities via PowerShell remoting.
This repository contains a functional exploit for CVE-2021-34473 (ProxyShell), which chains multiple vulnerabilities in Microsoft Exchange Server to achieve unauthenticated remote code execution. The exploit follows a multi-stage attack, including SSRF, SID manipulation, and PowerShell remoting to deploy a webshell.
Nuclei Templates (1)
vuln:cve-2021-26855 || http.favicon.hash:1768726119 || http.title:"outlook" || cpe:"cpe:2.3:a:microsoft:exchange_server"
title="outlook" || icon_hash=1768726119
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N