Executive brief
A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Exchange Server allows an unauthenticated attacker to send arbitrary HTTP requests and authenticate as the Exchange server. This vulnerability is a primary component of the ProxyLogon exploit chain, often leading to remote code execution.
Affected products
- Microsoft Exchange Server
Timeline
- 2021-03-02: advisory: Microsoft released security guidance for CVE-2021-26855.
- 2021-11-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
- 2021-11-03: disclosed: Public disclosure date.