Microsoft CVE-2021-26857: Microsoft Exchange Server Remote Code Execution Vulnerability (HAFNIUM Exploited)
Description
There exists an insecure deserialization vulnerability in the Unified Messaging service. Insecure deserialization is where untrusted user-controllable data is deserialized by a program. Exploiting this vulnerability gave HAFNIUM the ability to run code as SYSTEM on the Exchange server. This requires administrator permission or another vulnerability to exploit.
Solution(s)
msft-kb5000871-2dbdda16-f1ba-4b6a-891c-f92d6c05647cmsft-kb5000871-30386cf9-1373-4798-90b7-056d667875b3msft-kb5000871-3ef89683-3703-4a5d-b855-38579ba99a85msft-kb5000871-c6ed44ca-634b-4b5c-91ba-12232d8ec98emsft-kb5000871-dbbef9bc-f60b-4ee9-9d7d-22899fe76e70msft-kb5000978-4ecf02e7-963b-42d5-8c3d-07c90ec7f059
Referenceshttps://attackerkb.com/topics/cve-2021-26857CVE - 2021-2685750008715000978https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/