Input validation error in Microsoft Exchange Server - CVE-2021-26857
Published: March 2, 2021 / Updated: May 24, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send specially crafted data to the Exchange server and execute arbitrary code on the system.
Note, this vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2021-26857
Links to Public Exploits and PoC-codes
- Exploit #5259 - exprolog (ProxyLogon Full Exploit Chain PoC (CVE-2021–26855, CVE-2021–26857, CVE-2021–26858, CVE-2021–27065)) (April 1, 2021)
- Exploit #5221 - ProxyLogon (Chaining CVE-2021-26855 and CVE-2021-26857 to exploit Microsoft Exchange) (March 18, 2021)
- Exploit #5212 - Proxylogon-exploit (proxylogon exploit - CVE-2021-26857) (March 12, 2021)