Thursday, March 4, 2021

Microsoft CVE-2021-27065: Microsoft Exchange Server Remote Code Execution Vulnerability (HAFNIUM Exploited)

Description
There exists a post-authentication arbitrary file write vulnerability in Exchange. If HAFNIUM could authenticate with the Exchange server then they could use this vulnerability to write a file to any path on the server. They could authenticate by exploiting the CVE-2021-26855 SSRF vulnerability or by compromising a legitimate admin’s credentials.
Solution(s)
  • msft-kb5000871-2dbdda16-f1ba-4b6a-891c-f92d6c05647c
  • msft-kb5000871-30386cf9-1373-4798-90b7-056d667875b3
  • msft-kb5000871-3ef89683-3703-4a5d-b855-38579ba99a85
  • msft-kb5000871-c6ed44ca-634b-4b5c-91ba-12232d8ec98e
  • msft-kb5000871-dbbef9bc-f60b-4ee9-9d7d-22899fe76e70


  • References
  • https://attackerkb.com/topics/cve-2021-27065
  • CVE - 2021-27065
  • 5000871
  • https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/




  •  

    Copyright © 2021 Vulnerability Database | Cyber Details™

    thank you Templateism for the design - You should have written the code a little more complicated - Nothing Encrypted anymore