ZeroHour

CVE-2021-26858

KEV ransomwaremass

Post-Authentication RCE in On-Premises Microsoft Exchange Server (ProxyLogon)

CISA: Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 3.1
7.8 high
EPSS
94%p100
Published
()
KEV added
AI analysis

CVE-2021-26858 is a remote code execution vulnerability in on-premises Microsoft Exchange Server that stems from a post-authentication arbitrary file write, letting an authenticated attacker write attacker-controlled files to the server and execute code. In the wild it was almost always triggered as part of the 'ProxyLogon' chain together with the unauthenticated server-side request forgery flaw CVE-2021-26855, which allowed unauthenticated attackers to reach the vulnerable Exchange components through the front end. Successful exploitation yields code execution on the Exchange server, access to mailbox data, webshell persistence, and a foothold for lateral movement; Chinese espionage actors (e.g., Hafnium and related China-linked groups) used it in mass campaigns, and ransomware operators later leveraged it as well. Any organization running unpatched on-premises Exchange Server is affected; cloud-hosted Exchange Online is not. Exploitation is confirmed in the wild: the flaw is in CISA's KEV (added 2021-11-03) with known ransomware use, and EPSS assigns a 93.7% probability of exploitation within 30 days.

What to do: Apply the vendor's Exchange Server security updates per Microsoft's instructions immediately, as required by CISA's KEV; because this flaw is typically chained with the unauthenticated SSRF (CVE-2021-26855), patch the full set of associated Exchange vulnerabilities together. Hunt for signs of compromise on any server that has not yet applied the updates, including unexpected ASPX webshells in Exchange HTTP proxy directories and anomalous activity in Exchange (ECP/OAB) logs, and check for persistence and follow-on ransomware activity.

Affected
microsoft Exchange Server (on-premises)
Estimated exposure
mass≈500,000+ internet-exposed on-premises Exchange servers (order of magnitude) — Internet-wide scan estimates around the time of disclosure found hundreds of thousands of exposed on-premises Exchange servers, and on-premises Exchange is the default mail platform across large numbers of enterprise and SMB networks.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Exchange Server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
exchange server
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news