Code Injection in Microsoft Exchange Server - CVE-2021-34473
Published: July 13, 2021 / Updated: January 2, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation in the Microsoft Exchange Server. A remote attacker can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
How to mitigate CVE-2021-34473
Links to Public Exploits and PoC-codes
- Exploit #9478 - CVE-2021-34473 (CVE-2021-34473 Microsoft Exchange Server Remote Code Execution Vulnerability) (January 2, 2024)
- Exploit #6712 - proxyshell (Proof of Concept for CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) (September 7, 2021)
- Exploit #6639 - Microsoft Exchange ProxyShell RCE (August 19, 2021)
- Exploit #6627 - CVE-2021-34473 (CVE-2021-34473 Microsoft Exchange Server Remote Code Execution Vulnerability) (August 16, 2021)
- Exploit #6615 - CVE-2021-34473-scanner (Scanner for CVE-2021-34473, ProxyShell, A Microsoft Exchange On-premise Vulnerability) (August 11, 2021)