Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)
CVE-2021-28480
Verified
Description
Microsoft Exchange Server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server.
Severity
Critical
CVSS Score
9.8
Exploit Probability
71%
Affected Product
exchange_server
Published Date
January 20, 2026
Template Author
daffainfo
CVE-2021-28480.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2021-28480
CWE ID:
d-cwe-noinfo
References
https://sec.vnpt.vn/2021/04/microsoft-exchange-from-deserialization-to-post-auth-rce-cve-2021-28482https://hitcon.org/2021/agenda/279d7810-e619-4dc3-9113-b11bad5277ec/The%20Proxy%20Era%20of%20Microsoft%20Exchange%20Server.pdfhttps://www.youtube.com/watch?v=vn4niT9XEIMhttps://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-28480https://nvd.nist.gov/vuln/detail/cve-2021-28480
Remediation Steps
Apply the latest security patches and updates provided by Microsoft for Exchange Server