cbcvebase.
CVE-2021-26855
published 2021-03-03

CVE-2021-26855: Microsoft Exchange Server Remote Code Execution Vulnerability

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
100.00%
100.0th percentile
Microsoft Exchange Server Remote Code Execution Vulnerability

Affected

49 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftmicrosoft_exchange_server_2013_cumulative_update_21>= 15.00.0 < publicationpublication
microsoftmicrosoft_exchange_server_2013_cumulative_update_22>= 15.00.0 < publicationpublication
microsoftmicrosoft_exchange_server_2013_cumulative_update_23>= 15.00.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_10>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_11>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_12>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_13>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_14>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_15>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_16>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_17>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_18>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_19>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_8>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_9>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_1>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_2>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_3>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_4>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_5>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_6>= 15.02.0 < publicationpublication

Detection & IOCsextracted from sources · hover to see the quote

ip45.76.84.36
domainmail.prowesoo.com
domainmail.aztecoo.com
hashf32866258b67f041dc7858a59ea8afcd1297579ef50d4ebcec8775c816eb2da9
hash5d803a47d6bb7f68d4e735262bb7253def6aaab03122b05fec468865a1babe32
hashab678bbd30328e20faed53ead07c2f29646eb8042402305264388543319e949c
pathC:\inetpub\wwwroot\aspnet_client\client.aspx
pathC:\inetpub\wwwroot\aspnet_client\discover.aspx
path\inetpub\wwwroot\aspnet_client\system_web\
path\FrontEnd\HttpProxy\owa\auth\
filenamediscover.aspx
filename1302992a.aspx
filenameHttpProxy.aspx
filenamemsf.exe
filenameSRVCON.OCX
filenamerapi.dll
otherHTML.Exploit.CVE-2021-26855
otherHTML.Webshell.Hafnium
otherWin32.Backdoor.Hafnium
otherWin32.Ransom.DearCry
otherWin32.Exploit.Nishang
otherPS.Hacked.PowerCat
otherWin32.Trojan.ProcdumpExfil
otherWin64.Trojan.ProcdumpExfil
otherRansom:Win32/DoejoCrypt.A
  • Web shells dropped by Calypso APT post-exploitation are found at C:\inetpub\wwwroot\aspnet_client\client.aspx and C:\inetpub\wwwroot\aspnet_client\discover.aspx — hunt for unexpected .aspx files in these directories.
  • Hunt for unexpected .aspx files under \inetpub\wwwroot\aspnet_client\system_web\ and \FrontEnd\HttpProxy\owa\auth\ as indicators of web shell implantation.
  • Monitor for victim Exchange server IPs initiating outbound connections to PlugX C2 91.220.203.86 (yolkish[.]com) — a large spike in such traffic from Exchange hosts is a strong exploitation indicator.
  • Post-exploitation DLL search-order hijacking is used to load PlugX (SRVCON.OCX) and Whitebird (rapi.dll) via legitimate executables — monitor for unexpected DLL loads from Exchange server directories.
  • CVE-2021-26855 is an SSRF vulnerability; detection requires SSL/TLS decryption of Exchange HTTPS traffic on port 443 to inspect the exploit payload in encrypted traffic.
  • Patching Exchange does NOT remove already-implanted web shells; after patching, actively scan Exchange directories for residual .aspx web shells using IOC plugin 147193 or equivalent.
  • Alert on and block connections to all domains and IPs in the Calypso APT infrastructure cluster (membrig.com, draconess.com, rosyfund.com, sultris.com, yolkish.com, prowesoo.com, waxgon.com, rawfuns.com, aztecoo.com) at the network perimeter.
  • ·SSL decryption of Exchange HTTPS traffic is required for network-based detection of CVE-2021-26855 exploit attempts; IDS/IPS without decryption will miss encrypted attacks.
  • ·The IOC plugin (Tenable plugin ID 147193) only triggers on Exchange Servers where potential IOCs have been found within identified Exchange Server paths — a non-trigger does not confirm the host is uncompromised.
  • ·The list of known-bad filenames and hashes for Exchange web shells is continuously growing as more threat actors exploit the vulnerability — static IOC lists will become stale quickly.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.1CRITICAL
cisa9.8CRITICAL
vendor_msrc9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.