.. / CVE-2021-26855

Exploit for Microsoft Exchange Server SSRF Vulnerability (CVE-2021-26855)

Description:

This vulnerability is part of an attack chain that could allow remote code execution on Microsoft Exchange Server. The initial attack requires the ability to make an untrusted connection to Exchange server port 443. Other portions of the chain can be triggered if an attacker already has access or can convince an administrator to open a malicious file. Be aware his CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, and CVE-2021-27078.

Nuclei Template

View the template here CVE-2021-26855.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-26855.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2021-26855
https://proxylogon.com/#timeline
https://gist.github.com/testanull/324546bffab2fe4916d0f9d1f03ffa09
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-26855
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26855
https://web.archive.org/web/20210306113850/https://raw.githubusercontent.com/microsoft/CSS-Exchange/main/Security/http-vuln-cve2021-26855.nse