Summary
Microsoft Exchange Server’s ECP and OAB handling contains a post-authentication arbitrary file write flaw. An attacker with authenticated Exchange access can abuse crafted ECP requests and virtual-directory settings to write files to attacker-chosen paths, often dropping a web shell. In the ProxyLogon chain, this vulnerability can be combined with the earlier authentication bypass to reach unauthenticated remote code execution and broader server compromise.
Why Planned Fix?
4/6Exploitation Details
Write arbitrary files to attacker-chosen paths, enabling web-shell deployment and code execution
RCE (Remote Code Execution)Affected Software
| Product | Affected Versions |
|---|---|
| Microsoft Exchange Server | 2013 SP1 and CU21 through CU23, 2016 CU8 through CU19, 2019 RTM through CU8 |
On-premises Microsoft Exchange Server is an enterprise email, calendaring, and messaging platform for mailboxes, shared calendars, and collaboration.
Affected ComponentExchange Control Panel (ECP) and Offline Address Book (OAB) virtual directory handling, especially ECP DDI requests that modify virtual-directory URL properties.
Exchange Control Panel (ECP) and Offline Address Book (OAB) virtual directory handling, especially ECP DDI requests that modify virtual-directory URL properties.
Affected Endpoints(2)/ecp/DDI/DDIService.svc/SetObject, /ecp/DDI/DDIService.svc/GetObject…
Temporarily disable the Exchange Control Panel and Offline Address Book virtual directories using Microsoft's mitigation tooling (EOMT.ps1 or ExchangeMitigations.ps1) until patching is completed.
Temporarily disable the Exchange Control Panel and Offline Address Book virtual directories using Microsoft's mitigation tooling (EOMT.ps1 or ExchangeMitigations.ps1) until patching is completed.
Apply Microsoft security update KB5000871 for the affected Exchange Server cumulative update or service pack, then reboot as required.
Apply Microsoft security update KB5000871 for the affected Exchange Server cumulative update or service pack, then reboot as required.
Not available
Probability of exploitation in the next 30 days
Worse than 100% of all CVEs
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Affected Software (CPE) (22)
- •cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_21:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2013:sp1:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_10:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_11:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_12:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_13:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_14:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_15:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_16:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_17:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_18:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_8:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:-:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_1:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_2:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_3:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_4:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_5:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_6:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_7:*:*:*:*:*:*
- •cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| www.microsoft.com | HAFNIUM targeting Exchange Servers with 0-day exploits |
| www.microsoft.com | Microsoft Exchange Server Vulnerabilities Mitigations - updated March 15, 2021 |
| www.microsoft.com | Exploit:ASP/CVE-2021-27065 |
| support.microsoft.com | Exchange Server security update KB5000871 |
| nvd.nist.gov | CVE-2021-27065 Detail |
| microsoft.github.io | Test-ProxyLogon |
| www.tenable.com | CVE-2021-27065 |
| www.cisa.gov | Known Exploited Vulnerabilities Catalog |
| www.ic3.gov | Joint Cybersecurity Advisory: Compromise of Microsoft Exchange Server |
| packetstormsecurity.com | Microsoft Exchange ProxyLogon Remote Code Execution |
Priority History
Initial analysis