Microsoft Exchange Server是美国微软(Microsoft)公司的一套电子邮件服务程序。它提供邮件存取、储存、转发,语音邮件,邮件过滤筛选等功能。 Microsoft Exchange Server 安全漏洞。攻击者可构造恶意HTTP请求,并通过Exchange Server进行身份验证。进而扫描内网,获取用户敏感信息。以下产品和版本受到影响:Microsoft Exchange Server 2013 Cumulative Update 23,Microsoft Exchange
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | IoC determination for exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065. | https://github.com/sgnls/exchange-0days-202103 | POC Details |
| 2 | A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865 | https://github.com/soteria-security/HAFNIUM-IOC | POC Details |
| 3 | Detect webshells dropped on Microsoft Exchange servers exploited through "proxylogon" group of vulnerabilites (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) | https://github.com/cert-lv/exchange_webshell_detection | POC Details |
| 4 | Microsoft Exchange Server SSRF漏洞(CVE-2021-26855) | https://github.com/conjojo/Microsoft_Exchange_Server_SSRF_CVE-2021-26855 | POC Details |
| 5 | This script helps to identify CVE-2021-26855 ssrf Poc | https://github.com/pussycat0x/CVE-2021-26855-SSRF | POC Details |
| 6 | CVE-2021-26855 SSRF Exchange Server | https://github.com/La3B0z/CVE-2021-26855-SSRF-Exchange | POC Details |
| 7 | Module pack for #ProxyLogon (part. of my contribute for Metasploit-Framework) [CVE-2021-26855 && CVE-2021-27065] | https://github.com/mekhalleh/exchange_proxylogon | POC Details |
| 8 | POC of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865, ProxyLogon poc | https://github.com/Yt1g3r/CVE-2021-26855_SSRF | POC Details |
| 9 | CVE-2021-26855 exp | https://github.com/hackerxj007/CVE-2021-26855 | POC Details |
| 10 | A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin (CVE-2021-26855). | https://github.com/dwisiswant0/proxylogscan | POC Details |
| 11 | This script test the CVE-2021-26855 vulnerability on Exchange Server. | https://github.com/mauricelambert/ExchangeWeaknessTest | POC Details |
| 12 | CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065 | https://github.com/DCScoder/Exchange_IOC_Hunter | POC Details |
| 13 | PoC exploit code for CVE-2021-26855 | https://github.com/srvaccount/CVE-2021-26855-PoC | POC Details |
| 14 | None | https://github.com/h4x0r-dz/CVE-2021-26855 | POC Details |
| 15 | None | https://github.com/alt3kx/CVE-2021-26855_PoC | POC Details |
| 16 | CVE-2021-26855, also known as Proxylogon, is a server-side request forgery (SSRF) vulnerability in Exchange that allows an attacker to send arbitrary HTTP requests and authenticate as the Exchange server. | https://github.com/raheel0x01/CVE-2021-26855 | POC Details |
| 17 | PoC of proxylogon chain SSRF(CVE-2021-26855) to write file by testanull, censored by github | https://github.com/hackerschoice/CVE-2021-26855 | POC Details |
| 18 | CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065 | https://github.com/SCS-Labs/HAFNIUM-Microsoft-Exchange-0day | POC Details |
| 19 | Scanner and PoC for CVE-2021-26855 | https://github.com/KotSec/CVE-2021-26855-Scanner | POC Details |
| 20 | RCE exploit for Microsoft Exchange Server (CVE-2021-26855). | https://github.com/hakivvi/proxylogon | POC Details |
| 21 | CVE-2021-26855: PoC (Not a HoneyPoC for once!) | https://github.com/ZephrFish/Exch-CVE-2021-26855 | POC Details |
| 22 | RCE exploit for ProxyLogon vulnerability in Microsoft Exchange | https://github.com/mil1200/ProxyLogon-CVE-2021-26855 | POC Details |
| 23 | CVE-2021-26855 & CVE-2021-27065 | https://github.com/evilashz/ExchangeSSRFtoRCEExploit | POC Details |
| 24 | patched to work | https://github.com/ZephrFish/Exch-CVE-2021-26855_Priv | POC Details |
| 25 | None | https://github.com/Mr-xn/CVE-2021-26855-d | POC Details |
| 26 | ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin. We have also chained this bug with another post-auth arbitrary-file-write vulnerability, CVE-2021-27065, to get code execution. | https://github.com/RickGeex/ProxyLogon | POC Details |
| 27 | Chaining CVE-2021-26855 and CVE-2021-26857 to exploit Microsoft Exchange | https://github.com/Immersive-Labs-Sec/ProxyLogon | POC Details |
| 28 | None | https://github.com/shacojx/Scan-Vuln-CVE-2021-26855 | POC Details |
| 29 | CVE-2021-26855 proxyLogon metasploit exploit script | https://github.com/TaroballzChen/ProxyLogon-CVE-2021-26855-metasploit | POC Details |
| 30 | ProxyLogon(CVE-2021-26855+CVE-2021-27065) Exchange Server RCE(SSRF->GetWebShell) | https://github.com/p0wershe11/ProxyLogon | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-27078 | 9.1 CRITICAL | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-26412 | 9.1 CRITICAL | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-27065 | 7.8 HIGH | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-26858 | 7.8 HIGH | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-26857 | 7.8 HIGH | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-26854 | 6.6 MEDIUM | Microsoft Exchange Server Remote Code Execution Vulnerability |
No comments yet