Armis Logo< Back

CVE-2021-26855:

Microsoft Exchange Server SSRF Vulnerability (ProxyLogon) - CVE-2021-26855


Score
Info
A numerical rating that indicates how dangerous this vulnerability is.

9.8Critical
  • Published Date:Mar 3, 2021
  • CISA KEV Date:Nov 3, 2021
  • Industries Affected:20
Armis Early Warning:
Early Warning245 Days

Threat Predictions

  • EPSS Score:94.4
  • EPSS Percentile:100%

Exploitability

  • Score:3.9
  • Attack Vector:NETWORK
  • Attack Complexity:LOW
  • Privileges Required:NONE
  • User Interaction:NONE
  • Scope:UNCHANGED

Impact

  • Score:5.9
  • Confidentiality Impact:HIGH
  • Integrity Impact:HIGH
  • Availability Impact:HIGH

Description Preview

Microsoft Exchange Server SSRF Vulnerability (ProxyLogon) - CVE-2021-26855

Overview

The vulnerability exists in the Exchange Server's Unified Messaging service and allows attackers to bypass authentication and impersonate the Exchange server. By exploiting this SSRF vulnerability (CWE-918), attackers can forge requests that appear to originate from the server itself, which can lead to unauthorized access to sensitive information. When chained with other vulnerabilities (like CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065), attackers can achieve remote code execution on vulnerable Exchange servers. This vulnerability has been widely exploited by multiple threat actors, including nation-state groups, to deploy web shells, steal data, and establish persistent access to victim environments.

Remediation

  • 1. Apply the security updates released by Microsoft immediately:
  • For Exchange Server 2013: KB5001755
  • For Exchange Server 2016 and 2019: KB5001779
  • For Exchange Server 2010: KB5001746
  • 2. If immediate patching is not possible, implement Microsoft's recommended mitigations:
  • Implement URL Rewrite Rules to block known attack patterns
  • Restrict untrusted connections to Exchange Server
  • Use Microsoft Safety Scanner to detect potential compromises
  • 3. After patching:
  • Run Microsoft's Exchange On-premises Mitigation Tool (EOMT)
  • Scan for indicators of compromise using Microsoft's detection scripts
  • Check for web shells or unauthorized modifications to Exchange server files
  • Review authentication logs for suspicious activity
  • Consider resetting credentials for accounts with administrative access to Exchange
  • 4. Long-term recommendations:
  • Consider migrating to Exchange Online to benefit from cloud security features
  • Implement network segmentation for on-premises Exchange servers
  • Deploy advanced threat protection solutions
  • Regularly apply security updates as they become available

References

Early WarningArmis Early Warning

Armis Early Warning provides proactive threat intelligence and early detection capabilities.Click here to learn more.

  • Armis Alert Date:Mar 3, 2021
  • CISA KEV Date:Nov 3, 2021
  • Days Early:245 Days

Industries Affected

Below is a list of industries most commonly impacted or potentially at risk based on intelligence.

Low
Mining icon
Mining
Utilities icon
Utilities
Information icon
Information
Construction icon
Construction
Retail Trade icon
Retail Trade
Manufacturing icon
Manufacturing
Wholesale Trade icon
Wholesale Trade
Educational Services icon
Educational Services
Finance and Insurance icon
Finance and Insurance
Public Administration icon
Public Administration
Real Estate Rental and Leasing icon
Real Estate Rental and Leasing
Transportation and Warehousing icon
Transportation and Warehousing
Accommodation and Food Services icon
Accommodation and Food Services
Health Care and Social Assistance icon
Health Care and Social Assistance
Arts, Entertainment, and Recreation icon
Arts, Entertainment, and Recreation
Management of Companies and Enterprises icon
Management of Companies and Enterprises
Agriculture, Forestry, Fishing and Hunting icon
Agriculture, Forestry, Fishing and Hunting
Other Services (except Public Administration) icon
Other Services (except Public Administration)
Professional, Scientific, and Technical Services icon
Professional, Scientific, and Technical Services
Administrative and Support and Waste Management and Remediation Services icon
Administrative and Support and Waste Management and Remediation Services

Focus on What Matters

See everything.Identify true risk.Proactively mitigate threats.Book a Demo

Let's talk!