Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)
CVE-2021-28481
Verified
Description
Microsoft Exchange Server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server.
Severity
Critical
CVSS Score
9.8
Exploit Probability
36%
Affected Product
exchange_server
Published Date
January 20, 2026
Template Author
daffainfo
CVE-2021-28481.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2021-28481
CWE ID:
d-cwe-noinfo
References
https://sec.vnpt.vn/2021/04/microsoft-exchange-from-deserialization-to-post-auth-rce-cve-2021-28482https://hitcon.org/2021/agenda/279d7810-e619-4dc3-9113-b11bad5277ec/The%20Proxy%20Era%20of%20Microsoft%20Exchange%20Server.pdfhttps://www.youtube.com/watch?v=vn4niT9XEIMhttps://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-28481https://nvd.nist.gov/vuln/detail/cve-2021-28481
Remediation Steps
Apply the latest security patches and updates provided by Microsoft for Exchange Server