cbcvebase.
CVE-2021-27065
published 2021-03-03

CVE-2021-27065: Microsoft Exchange Server Remote Code Execution Vulnerability

PriorityP193high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.95%
100.0th percentile
Microsoft Exchange Server Remote Code Execution Vulnerability

Affected

50 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftmicrosoft_exchange_server_2013_cumulative_update_21>= 15.00.0 < publicationpublication
microsoftmicrosoft_exchange_server_2013_cumulative_update_22>= 15.00.0 < publicationpublication
microsoftmicrosoft_exchange_server_2013_cumulative_update_23>= 15.00.0 < publicationpublication
microsoftmicrosoft_exchange_server_2013_service_pack_1>= 15.00.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_10>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_11>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_12>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_13>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_14>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_15>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_16>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_17>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_18>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_19>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_8>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_9>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_1>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_2>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_3>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_4>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_5>= 15.02.0 < publicationpublication

Detection & IOCsextracted from sources · hover to see the quote

ip45.76.84.36
domainmail.prowesoo.com
domainmail.aztecoo.com
hashf32866258b67f041dc7858a59ea8afcd1297579ef50d4ebcec8775c816eb2da9
hash5d803a47d6bb7f68d4e735262bb7253def6aaab03122b05fec468865a1babe32
hashab678bbd30328e20faed53ead07c2f29646eb8042402305264388543319e949c
pathC:\inetpub\wwwroot\aspnet_client\client.aspx
pathC:\inetpub\wwwroot\aspnet_client\discover.aspx
filenamediscover.aspx
path\inetpub\wwwroot\aspnet_client\system_web\
path\FrontEnd\HttpProxy\owa\auth\
filename1302992a.aspx
filenameHttpProxy.aspx
filenamemsf.exe
filenameSRVCON.OCX
filenamerapi.dll
otherHTML.Exploit.CVE-2021-26855
otherHTML.Webshell.Hafnium
otherWin32.Backdoor.Hafnium
  • CVE-2021-27065 is a post-authentication arbitrary file write vulnerability in Exchange; attackers chain it with CVE-2021-26855 (SSRF/auth bypass) to write JScript web shells to arbitrary paths on the server.
  • Hunt for unexpected .aspx files in Exchange web-accessible directories: \inetpub\wwwroot\aspnet_client\, \inetpub\wwwroot\aspnet_client\system_web\, and \FrontEnd\HttpProxy\owa\auth\.
  • Calypso APT post-exploitation activity involves DLL search-order hijacking using legitimate executables to load PlugX (SRVCON.OCX) and Whitebird (rapi.dll) malware.
  • Monitor for outbound C2 traffic from Exchange servers to the PlugX C2 IP 91.220.203.86 (hosting yolkish.com); a large spike in victim Exchange IPs communicating with this host was observed from March 1, 2021.
  • SSL/TLS decryption of port 443 Exchange traffic is required to detect ProxyLogon/CVE-2021-27065 exploit attempts within encrypted sessions.
  • Use Tenable plugin ID 147193 to scan Exchange server directories for unexpected .aspx files indicative of web shell implantation via CVE-2021-27065 exploitation.
  • After patching, verify that web shells have been removed; patching does not remove already-implanted web shells, and other threat actors actively scan for and reuse existing shells.
  • ·Affected products are on-premises Exchange Server 2013, 2016, and 2019 only; Exchange Online is not affected.
  • ·The Calypso APT infrastructure cluster domains were registered as far back as 2018 and kept operational for more than 2 years, meaning blocklist entries for these domains/IPs should be treated as long-lived indicators.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.