Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Very High
CVE-2021-34473
Disclosure Date: July 14, 2021 (last updated November 28, 2024)
Microsoft Exchange Server Remote Code Execution Vulnerability
4
Attacker Value
Very High
ProxyShell Exploit Chain
Last updated December 28, 2023
ProxyShell is an exploit chain targeting on-premise installations of Microsoft Exchange Server. It was demonstrated by Orange Tsai at Pwn2Own in April 2021 and is comprised of three CVEs that, when chained, allow a remote unauthenticated attacker to execute arbitrary code on vulnerable targets. The three CVEs are CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207.
Details are available in Orange Tsai's [Black Hat USA 2020 talk](https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-ProxyLogon-Is-Just-The-Tip-Of-The-Iceberg-A-New-Attack-Surface-On-Microsoft-Exchange-Server.pdf) and follow-on [blog series](https://blog.orange.tw/2021/08/proxylogon-a-new-attack-surface-on-ms-exchange-part-1.html). ProxyShell is being broadly exploited in the wild as of August 12, 2021.
11
Attacker Value
Very High
CVE-2021-34523
Disclosure Date: July 14, 2021 (last updated November 28, 2024)
Microsoft Exchange Server Elevation of Privilege Vulnerability
2