Executive brief
Microsoft Exchange Server contains a Server-Side Request Forgery (SSRF) vulnerability, part of the 'ProxyShell' exploit chain, that allows an unauthenticated attacker to execute arbitrary code remotely. The vulnerability stems from improper validation of URI paths, enabling attackers to bypass authentication and access backend components.
Affected products
- Microsoft Exchange Server 2013 Cumulative Update 23
- Microsoft Exchange Server 2016 Cumulative Update 19, Cumulative Update 20
- Microsoft Exchange Server 2019 Cumulative Update 8, Cumulative Update 9
Timeline
- 2021-07-14: disclosed: NVD Published Date
- 2021-07-19: patched: MSRC advisory updated with patch information
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild per CISA KEV entry