cbcvebase.
CVE-2021-26858
published 2021-03-03

CVE-2021-26858: Microsoft Exchange Server Remote Code Execution Vulnerability

PriorityP190high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
89.51%
99.8th percentile
Microsoft Exchange Server Remote Code Execution Vulnerability

Affected

50 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftmicrosoft_exchange_server_2013_cumulative_update_21>= 15.00.0 < publicationpublication
microsoftmicrosoft_exchange_server_2013_cumulative_update_22>= 15.00.0 < publicationpublication
microsoftmicrosoft_exchange_server_2013_cumulative_update_23>= 15.00.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_10>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_11>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_12>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_13>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_14>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_15>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_16>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_17>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_18>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_19>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_8>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_9>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_1>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_2>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_3>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_4>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_5>= 15.02.0 < publicationpublication

Detection & IOCsextracted from sources · hover to see the quote

ip45.76.84.36
domainmail.prowesoo.com
domainmail.aztecoo.com
hashf32866258b67f041dc7858a59ea8afcd1297579ef50d4ebcec8775c816eb2da9
hash5d803a47d6bb7f68d4e735262bb7253def6aaab03122b05fec468865a1babe32
hashab678bbd30328e20faed53ead07c2f29646eb8042402305264388543319e949c
pathC:\inetpub\wwwroot\aspnet_client\client.aspx
pathC:\inetpub\wwwroot\aspnet_client\discover.aspx
filenamediscover.aspx
path\inetpub\wwwroot\aspnet_client\system_web\
path\FrontEnd\HttpProxy\owa\auth\
filename1302992a.aspx
filenameHttpProxy.aspx
domaint.hwqloan.com
domaind.hwqloan.com
domaint.ouler.cc
domainps2.jusanrihua.com
domaint.netcatkit.com
domaint.bb3u9.com
urlhttp://t.bb3u9.com/ipc.jsp?1.0
urlhttp://t.hwqloan.com/t.txt
hash6be5847c5b80be8858e1ff0ece401851886428b1f22444212250133d49b5ee30
filenameipc.jsp
filenameaa.jsp
filenamesyspstem.dat
  • Hunt for anomalous .aspx webshell files in Exchange Server directories: \inetpub\wwwroot\aspnet_client\, \inetpub\wwwroot\aspnet_client\system_web\, and \FrontEnd\HttpProxy\owa\auth\
  • Alert on and block connections to PlugX C2 IPs 91.220.203.86 and 91.220.203.197, especially from hosts running Microsoft Exchange services
  • Detect DLL search-order hijacking post-exploitation: look for SRVCON.OCX (PlugX Loader) and rapi.dll (Whitebird Loader) loaded by legitimate executables
  • Use Tenable plugin ID 147193 to scan Exchange Server directories for anomalous .aspx files as IOCs for Hafnium/ProxyLogon webshell implantation
  • Detect Lemon Duck WMIC-based AV removal activity: wmic.exe commands uninstalling ESET, Kaspersky, stopping wuauserv and Windows Defender post-Exchange compromise
  • Detect post-exploitation tools Nishang and PowerCat running on Exchange servers as indicators of HAFNIUM/ProxyLogon compromise
  • ·Patching Exchange Servers does NOT remove already-implanted webshells; IOC scanning for webshells must be performed even after patches are applied
  • ·Microsoft Exchange Server 2010 may also be vulnerable but is NOT covered by the four CVE patches issued March 2, 2021; separate defense-in-depth guidance applies
  • ·Restricting untrusted connections to port 443 only mitigates the initial CVE-2021-26855 step; other parts of the exploit chain (including CVE-2021-26858) can still be triggered if attackers already have access or trick an admin into running a malicious file
  • ·Webshells left behind by initial threat actors (e.g., HAFNIUM/Calypso) can be piggybacked by other threat actors scanning for them; removal is critical to prevent secondary compromise

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.