ZeroHour

CVE-2021-33766

KEVmass

Unauthenticated Information Disclosure (ProxyToken) in Microsoft Exchange Server

CISA: Microsoft Exchange Server Information Disclosure

CVSS 3.1
7.3 high
EPSS
98%p100
Published
()
KEV added
AI analysis

CVE-2021-33766, publicly known as 'ProxyToken', is an information disclosure vulnerability caused by an authentication bypass in the Exchange Control Panel (ECP) of Microsoft Exchange Server. An unauthenticated attacker sends specially crafted requests to the exposed ECP endpoint that abuse Exchange's default authentication-token handling in its proxy layer, so the backend treats the request as an authenticated session for another user's mailbox. The attacker gains access to victims' mailboxes — reading emails — and, as the related reporting notes, can reconfigure mailbox/server settings such as adding delegates or forwarding rules. Organizations running affected on-premises Exchange servers (Exchange Server 2016 and 2019 per Microsoft's advisory) with ECP/OWA exposed are affected; the cloud-hosted Exchange Online service is not. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-01-18 and EPSS estimates a 98.1% probability of exploitation within 30 days, though no public proof-of-concept is cataloged and ransomware use is unknown.

What to do: Apply the July 2021 security updates — or any later cumulative or security update — for Exchange Server 2016/2019, per Microsoft's instructions and CISA's KEV required action. Until patched, limit internet exposure of ECP/OWA and review mailbox audit logs, delegate assignments, and inbox forwarding rules for signs of tampering, since ProxyToken has been used to read mail and reconfigure mailboxes.

Affected
microsoft exchange serveron-premises Exchange Server 2016 and Exchange Server 2019 prior to the July 2021 Microsoft security updates
Estimated exposure
massseveral hundred thousand (order of 300,000–500,000) internet-exposed on-prem Exchange servers — Internet-wide scan reports and vendor counts during 2021 found on the order of 300,000–500,000 internet-exposed on-prem Exchange/OWA endpoints, and on-prem Exchange is deployed by hundreds of thousands of organizations, so the plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Exchange Server Information Disclosure Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Exchange Server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
exchange server
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news