Toutes les vulnérabilités
CRITICALInfraexploited in the wildransomware

CVE-2021-26855

Microsoft Exchange · Microsoft Exchange Server

Résumé

A server-side request forgery flaw in on-premises Exchange Server lets an unauthenticated attacker send arbitrary HTTP requests and authenticate as the Exchange server itself. It was the entry point in the ProxyLogon exploit chain, combined with CVE-2021-27065 for post-authentication RCE, enabling full unauthenticated remote code execution. Microsoft attributed initial zero-day exploitation to the China state-sponsored group HAFNIUM, but after the patch dropped at least ten threat groups mass-compromised servers. Microsoft reported roughly 400,000 vulnerable servers on March 1, 2021, and tens of thousands of organizations were breached.

Références

Vulnérabilités liées

Tout Infra →