PT-2021-2214 · Microsoft · Exchange Server

·

CVE-2021-26855

·

Published

2021-03-02

·

Updated

2026-09-02

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server (affected versions not specified)
Description Microsoft Exchange Server contains a flaw that allows remote attackers to execute arbitrary code. The issue is related to insufficient validation of incoming requests, enabling a Server-Side Request Forgery (SSRF) attack via specially crafted HTTPS requests. These requests utilize malicious X-AnonResource-Backend and distorted X-BEResource cookies to authenticate on the server. Real-world exploitation has been observed in campaigns targeting diplomatic organizations in Indonesia, government entities in Taiwan, and software developers across various countries including Lebanon, Syria, Colombia, North Macedonia, Nepal, and Serbia. In these incidents, the flaw was used to gain initial access and deploy the SharkLoader loader to install Cobalt Strike Beacon on compromised systems.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01123
CVE-2021-26855
EXCHANGECVE2021_26855

Affected Products

Exchange Server