Summary
Microsoft Exchange Server's front-end HTTP proxy contains a server-side request forgery flaw. An unauthenticated attacker can craft cookies and requests that make Exchange relay HTTP traffic to internal backend endpoints as the Exchange server itself. This was the initial ProxyLogon primitive used to reach authenticated Exchange functionality, expose mailbox data, and enable full server compromise when chained with related bugs.
Why Emergency Fix?
6/6Exploitation Details
Reach internal Exchange endpoints as the server and enable full server compromise in the ProxyLogon chain.
Full System CompromiseAffected Software
| Product | Affected Versions |
|---|---|
| Microsoft Exchange Server | 2010, 2013, 2016, and 2019 before KB5000871 |
Microsoft Exchange Server is an on-premises email and calendaring platform that hosts mailboxes, routes mail, and provides web access for Outlook and administrative management in enterprise environments.
Affected ComponentFront-end HttpProxy request routing in Exchange web services, especially ECP and Autodiscover proxy handling via the X-BEResource and related cookies.
Front-end HttpProxy request routing in Exchange web services, especially ECP and Autodiscover proxy handling via the X-BEResource and related cookies.
Affected Endpoints(4)/ecp/favicon.ico, /ecp/proxyLogon.ecp…
Temporarily filter malicious X-AnonResource-Backend and X-BEResource requests with IIS URL Rewrite, or disable Unified Messaging, ECP, and OAB virtual directories until patched.
Temporarily filter malicious X-AnonResource-Backend and X-BEResource requests with IIS URL Rewrite, or disable Unified Messaging, ECP, and OAB virtual directories until patched.
Install the March 2, 2021 Exchange security update KB5000871 for your supported cumulative update.
Install the March 2, 2021 Exchange security update KB5000871 for your supported cumulative update.
Not available
Probability of exploitation in the next 30 days
Worse than 100% of all CVEs
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Affected Software (CPE) (24)
- •cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_21:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_22:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_10:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_11:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_12:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_13:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_14:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_15:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_16:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_17:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_18:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_8:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_9:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:-:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_1:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_2:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_3:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_4:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_5:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_6:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_7:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| support.microsoft.com | Description of the security update for Microsoft Exchange Server 2019, 2016, and 2013: March 2, 2021 (KB5000871) |
| www.microsoft.com | HAFNIUM targeting Exchange Servers with 0-day exploits |
| msrc.microsoft.com | Guidance for responders: Investigating and remediating on-premises Exchange Server vulnerabilities |
| googleprojectzero.github.io | CVE-2021-26855: Microsoft Exchange Server-Side Request Forgery |
| nvd.nist.gov | CVE-2021-26855 Detail |
| www.cisa.gov | Known Exploited Vulnerabilities Catalog |
| github.com | Exchange Server support scripts - Security |
| www.snort.org | Rule Document 1:57241 |
| github.com | praetorian-inc/proxylogon-exploit |
Priority History
Initial analysis