CVE-2021-33766
KEVmassUnauthenticated Information Disclosure (ProxyToken) in Microsoft Exchange Server
CISA: Microsoft Exchange Server Information Disclosure
CVE-2021-33766, publicly known as 'ProxyToken', is an information disclosure vulnerability caused by an authentication bypass in the Exchange Control Panel (ECP) of Microsoft Exchange Server. An unauthenticated attacker sends specially crafted requests to the exposed ECP endpoint that abuse Exchange's default authentication-token handling in its proxy layer, so the backend treats the request as an authenticated session for another user's mailbox. The attacker gains access to victims' mailboxes — reading emails — and, as the related reporting notes, can reconfigure mailbox/server settings such as adding delegates or forwarding rules. Organizations running affected on-premises Exchange servers (Exchange Server 2016 and 2019 per Microsoft's advisory) with ECP/OWA exposed are affected; the cloud-hosted Exchange Online service is not. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-01-18 and EPSS estimates a 98.1% probability of exploitation within 30 days, though no public proof-of-concept is cataloged and ransomware use is unknown.
What to do: Apply the July 2021 security updates — or any later cumulative or security update — for Exchange Server 2016/2019, per Microsoft's instructions and CISA's KEV required action. Until patched, limit internet exposure of ECP/OWA and review mailbox audit logs, delegate assignments, and inbox forwarding rules for signs of tampering, since ProxyToken has been used to read mail and reconfigure mailboxes.
| microsoft exchange server | on-premises Exchange Server 2016 and Exchange Server 2019 prior to the July 2021 Microsoft security updates |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Exchange Server Information Disclosure Vulnerability
- Affected
- Microsoft Exchange Server
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- exchange server
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L