PT-2021-2214 · Microsoft · Exchange Server
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Exchange Server (affected versions not specified)
Description
Microsoft Exchange Server contains a flaw that allows remote attackers to execute arbitrary code. The issue is related to insufficient validation of incoming requests, enabling a Server-Side Request Forgery (SSRF) attack via specially crafted HTTPS requests. These requests utilize malicious
X-AnonResource-Backend and distorted X-BEResource cookies to authenticate on the server. Real-world exploitation has been observed in campaigns targeting diplomatic organizations in Indonesia, government entities in Taiwan, and software developers across various countries including Lebanon, Syria, Colombia, North Macedonia, Nepal, and Serbia. In these incidents, the flaw was used to gain initial access and deploy the SharkLoader loader to install Cobalt Strike Beacon on compromised systems.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exchange Server