momo安全漏洞库

多模块数据检索平台

登录 注册
返回列表

CVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)

CVE: CVE-2021-28480
CNVD: 暂无
CNNVD: 暂无
漏洞类型: 命令执行
漏洞等级: 严重
年份: 2026
POC_ID: 暂无
漏洞描述
Microsoft Exchange Server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server. [已公开] id: CVE-2021-28480 info: name: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound) author: daffainfo severity: critical description: | Microsoft Exchange Server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server. impact: | Attackers can execute arbitrary code remotely, potentially leading to full system compromise or data breach remediation: | Apply the latest security patches and updates provided by Microsoft for Exchange Server reference: - https://sec.vnpt.vn/2021/04/microsoft-exchange-from-deserialization-to-post-auth-rce-cve-2021-28482 - https://hitcon.org/2021/agenda/279d7810-e619-4dc3-9113-b11bad5277ec/The%20Proxy%20Era%20of%20Microsoft%20Exchange%20Server.pdf - https://www.youtube.com/watch?v=vn4niT9XEIM - https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-28480 - https://nvd.nist.gov/vuln/detail
影响范围
未知
漏洞详情
登录后可查看漏洞详情。请先 登录注册
漏洞 POC
登录后可查看漏洞 POC。请先 登录注册
修复建议
暂无