CVE-2021-34473
Microsoft Exchange Server Remote Code Execution Vulnerability
In short
A critical flaw in Microsoft Exchange Server allows attackers to execute arbitrary code remotely without authentication. This affects email servers worldwide and can lead to complete system compromise.
Technical detail
Server-Side Request Forgery (SSRF) vulnerability in Exchange Server's Autodiscover service allows unauthenticated attackers to bypass authentication mechanisms and achieve Remote Code Execution through malicious requests. The vulnerability enables execution of arbitrary PowerShell commands with System privileges, requiring only network access to the affected server.
Summary generated and translated by AI from the official description.
Microsoft Exchange Server Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
Affected products
Microsoft · Microsoft Exchange Server 2013 Cumulative Update 23Microsoft · Microsoft Exchange Server 2016 Cumulative Update 19Microsoft · Microsoft Exchange Server 2016 Cumulative Update 20Microsoft · Microsoft Exchange Server 2019 Cumulative Update 8Microsoft · Microsoft Exchange Server 2019 Cumulative Update 9public PoCs found — 9
githubgithub.com/horizon3ai/proxyshell★ 120githubgithub.com/cyberheartmi9/Proxyshell-Scanner★ 46githubgithub.com/kh4sh3i/ProxyShell★ 41githubgithub.com/p2-98/CVE-2021-34473★ 30githubgithub.com/je6k/CVE-2021-34473-Exchange-ProxyShell★ 17githubgithub.com/RaouzRouik/CVE-2021-34473-scanner★ 5githubgithub.com/ipsBruno/CVE-2021-34473-NMAP-SCANNER★ 2githubgithub.com/f4alireza/CVE★ 0cve_referencepacketstormsecurity.com/files/163895/Microsoft-Exchange-ProxyShell-Remote-Code-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://packetstormsecurity.com/files/163895/Microsoft-Exchange-ProxyShell-Remote-Code-Execution.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34473https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-34473https://www.zerodayinitiative.com/advisories/ZDI-21-821/