Server-Side Request Forgery (SSRF) in Microsoft Exchange Server - CVE-2021-26855
Published: March 2, 2021 / Updated: May 14, 2023
Vulnerability identifier: #VU51171
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N]
CVE-ID: CVE-2021-26855
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send specially crafted HTTP request to the Microsoft Exchange OWA interface, upload arbitrary file on the server and execute it.
Note, this vulnerability is being actively exploited in the wild.
Affected software
Microsoft Exchange Server
How to mitigate CVE-2021-26855
Install updates from vendor's website.
Links to Public Exploits and PoC-codes
- Exploit #9072 - CVE-2021-26855 (CVE-2021-26855 exp) (May 14, 2023)
- Exploit #8407 - Scan-Vuln-CVE-2021-26855 () (September 27, 2022)
- Exploit #8311 - CVE-2021-26855-SSRF-Exchange (CVE-2021-26855 SSRF Exchange Server) (August 29, 2022)
- Exploit #8083 - ProxyLogon (ProxyLogon (CVE-2021-26855+CVE-2021-27065) Exchange Server RCE (SSRF->GetWebShell)) (June 27, 2022)
- Exploit #8079 - ExchangeSmash (CVE-2021-26855) (June 26, 2022)
- Exploit #7244 - CVE-2021-26856 () (January 16, 2022)
- Exploit #6982 - CVE-2021-26855_SSRF (POC of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865, ProxyLogon poc) (November 3, 2021)
- Exploit #6787 - CVE-2021-26855-SSRF-Exchange (CVE-2021-26855 SSRF Exchange Server) (September 23, 2021)
- Exploit #6749 - CVE-2021-26855-d () (September 14, 2021)
- Exploit #6740 - ProxyVulns ([ProxyLogon] CVE-2021-26855 & CVE-2021-27065 Fixed RawIdentity Bug Exploit. [ProxyOracle] CVE-2021-31195 & CVE-2021-31196 Exploit Chains. [ProxyShell] CVE-2021-34473 & CVE-2021-34523 & CVE-2021-31207 Exploit Chains.) (September 12, 2021)
- Exploit #6644 - CVE_2021_26855_SSRF () (August 19, 2021)
- Exploit #6633 - ExchangeSSRFtoRCEExploit (CVE-2021-26855 & CVE-2021-27065) (August 18, 2021)
- Exploit #6626 - CVE-2021-26855 () (August 15, 2021)
- Exploit #6539 - CVE-2021-26855 (PoC of proxylogon chain SSRF(CVE-2021-26855) to write file by testanull, censored by github) (July 14, 2021)
- Exploit #6538 - CVE-2021-26855 (PoC for CVE-2021-26855 -Just a checker-) (July 12, 2021)
- Exploit #6537 - Microsoft_Exchange_Server_SSRF_CVE-2021-26855 (Microsoft Exchange Server SSRF漏洞(CVE-2021-26855)) (July 12, 2021)
- Exploit #5582 - Microsoft Exchange 2019 - Unauthenticated Email Download (Metasploit) (June 17, 2021)
- Exploit #5551 - ProxyLogon (ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin. We have also chained this bug with another post-auth (June 10, 2021)
- Exploit #5529 - exchange_proxylogon (Module pack for #ProxyLogon (part. of my contribute for Metasploit-Framework) [CVE-2021-26855 && CVE-2021-27065]) (June 6, 2021)
- Exploit #5528 - SharpProxyLogon (C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection ) (June 6, 2021)
- Exploit #5500 - CVE-2021-26855-SSRF (This script helps to identify CVE-2021-26855 ssrf Poc) (May 30, 2021)
- Exploit #5487 - proxylogscan (A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin (CVE-2021-26855).) (May 26, 2021)
- Exploit #5472 - CVE-2021-26855 (CVE-2021-26855 exp) (May 24, 2021)
- Exploit #5458 - Microsoft Exchange 2019 - Unauthenticated Email Download (May 20, 2021)
- Exploit #5425 - Check_Emails_For_CVE_2021_26855 () (May 18, 2021)
- Exploit #5424 - CVE-2021-26855_PoC () (May 18, 2021)
- Exploit #5387 - Microsoft Exchange ProxyLogon Collector (May 9, 2021)
- Exploit #5384 - Microsoft Exchange ProxyLogon Scanner (May 9, 2021)
- Exploit #5354 - Microsoft Exchange ProxyLogon RCE (May 9, 2021)
- Exploit #5293 - ProxyLogon (CVE-2021-26855 & CVE-2021-27065 Fixed RawIdentity Bug Exploit) (April 16, 2021)
- Exploit #5271 - eeb927d1189ad44742095f58636483984bfbfa355f69f94439e276df306d9568 (CVE-2021-26855, also known as Proxylogon, is a server-side request forgery (SSRF) vulnerability in Exchange that allows an attacker to send arbitrary HTTP requests and authenticate as the E (April 6, 2021)
- Exploit #5269 - CVE-2021-26855-exploit-Exchange () (April 6, 2021)
- Exploit #5258 - exprolog (ProxyLogon Full Exploit Chain PoC (CVE-2021–26855, CVE-2021–26857, CVE-2021–26858, CVE-2021–27065)) (April 1, 2021)
- Exploit #5244 - proxylogon-exploit (Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.) (March 26, 2021)
- Exploit #5241 - Server-Side Request Forgery (SSRF) (March 26, 2021)
- Exploit #5222 - ProxyLogon (ProxyLogon(CVE-2021-26855+CVE-2021-27065) Exchange Server RCE(SSRF->GetWebShell)) (March 18, 2021)
- Exploit #5220 - ProxyLogon (Chaining CVE-2021-26855 and CVE-2021-26857 to exploit Microsoft Exchange) (March 18, 2021)
- Exploit #5218 - ProxyLogon-CVE-2021-26855-metasploit (CVE-2021-26855 proxyLogon metasploit exploit script) (March 18, 2021)
- Exploit #5216 - CVE-2021-26855_Exchange (Microsoft Exchange Proxylogon Exploit Chain EXP分析) (March 18, 2021)
- Exploit #5215 - ProxyLogon-CVE-2021-26855 (RCE exploit for ProxyLogon vulnerability in Microsoft Exchange) (March 15, 2021)
- Exploit #5211 - CVE_2021_26855_Exploit_Hub () (March 12, 2021)
- Exploit #5209 - CVE-2021-26855-PoC (PoC exploit code for CVE-2021-26855) (March 12, 2021)
- Exploit #5206 - CVE-2021-26855 ( CVE-2021-26855, also known as Proxylogon, is a server-side request forgery (SSRF) vulnerability in Exchange that allows an attacker to send arbitrary HTTP requests and authenticate as the Exchange server.) (March 12, 2021)
- Exploit #5204 - RCE in Microsoft Exchange (CVE-2021-26855) (March 11, 2021)