Input validation error in Microsoft Exchange Server - CVE-2021-27065
Published: March 2, 2021 / Updated: June 27, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send specially crafted data to the Exchange server and execute arbitrary code on the system.
Note, this vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2021-27065
Links to Public Exploits and PoC-codes
- Exploit #8084 - ProxyLogon (ProxyLogon (CVE-2021-26855+CVE-2021-27065) Exchange Server RCE (SSRF->GetWebShell)) (June 27, 2022)
- Exploit #6739 - ProxyVulns ([ProxyLogon] CVE-2021-26855 & CVE-2021-27065 Fixed RawIdentity Bug Exploit. [ProxyOracle] CVE-2021-31195 & CVE-2021-31196 Exploit Chains. [ProxyShell] CVE-2021-34473 & CVE-2021-34523 & CVE-2021-31207 Exploit Chains.) (September 12, 2021)
- Exploit #6634 - ExchangeSSRFtoRCEExploit (CVE-2021-26855 & CVE-2021-27065) (August 18, 2021)
- Exploit #5581 - Microsoft Exchange 2019 - Unauthenticated Email Download (Metasploit) (June 17, 2021)
- Exploit #5552 - ProxyLogon (ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin. We have also chained this bug with another post-auth (June 10, 2021)
- Exploit #5530 - exchange_proxylogon (Module pack for #ProxyLogon (part. of my contribute for Metasploit-Framework) [CVE-2021-26855 && CVE-2021-27065]) (June 6, 2021)
- Exploit #5488 - proxylogscan (A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin (CVE-2021-26855).) (May 26, 2021)
- Exploit #5473 - CVE-2021-26855 (CVE-2021-26855 exp) (May 24, 2021)
- Exploit #5353 - Microsoft Exchange ProxyLogon RCE (May 9, 2021)
- Exploit #5294 - ProxyLogon (CVE-2021-26855 & CVE-2021-27065 Fixed RawIdentity Bug Exploit) (April 16, 2021)
- Exploit #5261 - exprolog (ProxyLogon Full Exploit Chain PoC (CVE-2021–26855, CVE-2021–26857, CVE-2021–26858, CVE-2021–27065)) (April 1, 2021)
- Exploit #5245 - proxylogon-exploit (Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.) (March 26, 2021)
- Exploit #5223 - ProxyLogon (ProxyLogon(CVE-2021-26855+CVE-2021-27065) Exchange Server RCE(SSRF->GetWebShell)) (March 18, 2021)