Microsoft Exchange SSRF漏洞(CVE-2021-26855) CVE-2021-26855 CNNVD-202103-192

7.5 AV AC AU C I A
发布: 2021-03-03
修订: 2024-11-21

## Operation Exchange Marauder: Active Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities March 2, 2021 by Josh Grunzweig, Matthew Meltzer, Sean Koessel, Steven Adair, Thomas Lancaster __Facebook __Twitter __Email ![](https://images.seebug.org/1614746963339-w331s) _**Volexity is seeing active in-the-wild exploitation of multiple Microsoft Exchange vulnerabilities used to steal e-mail and compromise networks. These attacks appear to have started as early as January 6, 2021.**_ _ _ In January 2021, through its Network Security Monitoring service, Volexity detected anomalous activity from two of its customers' Microsoft Exchange servers. Volexity identified a large amount of data being sent to IP addresses it believed were not tied to legitimate users. A closer inspection of the IIS logs from the Exchange servers revealed rather alarming results. The logs showed inbound POST requests to valid files associated with images, JavaScript, cascading style sheets, and fonts...

0%
当前有8条漏洞利用/PoC
当前有24条受影响产品信息