CVE-2021-26855
Microsoft Exchange Server SSRF vulnerability (ProxyLogon). Pre-authentication allows remote code execution with SSRF. HAFNIUM was actively used by APT and many threat actors to hijack Exchange servers.
Vulnerability Profile
CVSS Score
9.8 / 10.0
Severity
Critical
Exploitation Status
⚠ Active Exploitation
Patch Status
✓ Patch Available
Affected Software
Microsoft Exchange Server 2013/2016/2019
Exploitation Method
SSRF/RCE Chain
MITRE ATT&CK
T1190 - Exploit Public-Facing Application
CVE-2021-26855 (ProxyLogon) Microsoft Exchange Server SSRF acigi; HAFNIUM grubu tarafindan kesfedildi. Pre-auth isteklerle Exchange Calendar service uzerinden SSRF saglaniyor. Buna ek olarak CVE-2021-26857, CVE-2021-26858 ve CVE-2021-27065 ile zincirlenerek tam RCE saglanmaktadir. Patch: 2021-03-02