🔙 목록으로 돌아가기

CVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)

TitleMicrosoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)
Authordaffainfo
SeverityCritical
ImpactAttackers can execute arbitrary code remotely, potentially leading to full system compromise or data breach
RemediationApply the latest security patches and updates provided by Microsoft for Exchange Server
CVSS Score9.8
EPSS Score0.87131
CVE IDCVE-2021-28480
CWE IDD-CWE-noinfo
Shodan Queryhttp.favicon.hash:1768726119http.title:"outlook"cpe:"cpe:2.3:a:microsoft:exchange_server"
Fofa Querytitle="outlook"icon_hash=1768726119
Tags cve cve2021 ssrf rce exchange microsoft

🔍 Vulnerability Description

Microsoft Exchange Server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server.

🌐 HTTP Request

GET /owa/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.1.3 Safari/605.1.15
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-28480.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-28480.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A