ZeroHour

CVE-2021-26857

KEV ransomwaremass1

Deserialization RCE in Microsoft Exchange Server Unified Messaging (ProxyLogon)

CISA: Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 3.1
7.8 high
EPSS
96%p100
Published
()
KEV added
AI analysis

CVE-2021-26857 is an insecure deserialization (CWE-502) remote code execution flaw in the Unified Messaging service of Microsoft Exchange Server. Although Microsoft scored it as a local attack vector (CVSS 3.1 7.8), it was exploited in the wild as part of the four-zero-day 'ProxyLogon' chain alongside the CVE-2021-26855 server-side request forgery flaw, turning unauthenticated HTTP requests into arbitrary code execution. Successful exploitation gives an attacker code execution on the mail server, from which they can read mailboxes, plant webshells, and move laterally; CISA notes known ransomware use in addition to espionage activity. Only on-premises Exchange deployments are affected — Exchange Server 2013, 2016, and 2019 prior to Microsoft's March 2021 fixes — while Microsoft's hosted Exchange Online service was not. Exploitation is confirmed and ongoing: EPSS rates it at 95.8% exploitation probability, it has been in CISA's Known Exploited Vulnerabilities catalog since November 2021, and headlines show multiple China-linked APT groups (e.g., HAFNIUM-linked campaigns, Calypso APT, Silk Typhoon) continuing to target vulnerable Exchange servers.

What to do: Apply Microsoft's March 2021 security updates (KB5000871) or any later cumulative update for on-premises Exchange Server 2013, 2016, or 2019; as a stopgap, restrict or disable the Unified Messaging service if it is not used. Hunt for compromise by checking Unified Messaging application event logs for 'System.InvalidCastException' entries, HttpProxy/Autodiscover logs for anomalous requests, and signs of post-exploitation such as webshells or unexpected processes spawned by w3wp.exe or UMWorkerProcess. Because the flaw is in CISA's KEV catalog with known ransomware use, treat patching as a priority action and verify no residual webshells or attacker persistence after updating.

Affected
microsoft Exchange Server (on-premises)Exchange Server 2013, 2016, and 2019 before the March 2021 security updates (KB5000871)
Estimated exposure
masshundreds of thousands of on-premises Exchange servers worldwide, with tens of thousands still unpatched against the 2021 flaws per later internet scans — On-premises Exchange is one of the most widely deployed mail servers, and public internet scans around disclosure counted hundreds of thousands of internet-exposed Exchange/OWA endpoints, with subsequent scans finding tens of thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Exchange Server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
exchange server
Weakness
CWE-502
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news