/Vulnerability Library

Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)

CVE-2021-28481
Verified

Description

Microsoft Exchange Server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server.

Severity

Critical

CVSS Score

9.8

Exploit Probability

36%

Affected Product

exchange_server

Published Date

January 20, 2026

Template Author

daffainfo

CVE-2021-28481.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2021-28481
CWE ID:
d-cwe-noinfo

References

https://sec.vnpt.vn/2021/04/microsoft-exchange-from-deserialization-to-post-auth-rce-cve-2021-28482https://hitcon.org/2021/agenda/279d7810-e619-4dc3-9113-b11bad5277ec/The%20Proxy%20Era%20of%20Microsoft%20Exchange%20Server.pdfhttps://www.youtube.com/watch?v=vn4niT9XEIMhttps://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-28481https://nvd.nist.gov/vuln/detail/cve-2021-28481

Remediation Steps

Apply the latest security patches and updates provided by Microsoft for Exchange Server