漏洞信息详情

Microsoft Exchange Server 安全漏洞

  • CNNVD编号:CNNVD-202103-192
  • 危害等级: 超危
  • CVE编号: CVE-2021-26855
  • 漏洞类型: 其他
  • 发布时间: 2021-03-02
  • 威胁类型: 远程
  • 更新时间: 2021-05-24
  • 厂        商:
  • 漏洞来源: Ramella Sebastien

漏洞简介

Microsoft Exchange Server是美国微软(Microsoft)公司的一套电子邮件服务程序。它提供邮件存取、储存、转发,语音邮件,邮件过滤筛选等功能。

Microsoft Exchange Server 安全漏洞。攻击者可构造恶意HTTP请求,并通过Exchange Server进行身份验证。进而扫描内网,获取用户敏感信息。以下产品和版本受到影响:Microsoft Exchange Server 2013 Cumulative Update 23,Microsoft Exchange Server 2019 Cumulative Update 7,Microsoft Exchange Server 2016 Cumulative Update 18,Microsoft Exchange Server 2016 Cumulative Update 19,Microsoft Exchange Server 2019 Cumulative Update 8。

漏洞公告

目前厂商已发布升级补丁以修复漏洞,补丁获取链接:

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26855

参考网址

来源:MISC

链接:https://packetstormsecurity.com/files/161846/Microsoft-Exchange-2019-SSRF-Arbitrary-File-Write.html

来源:MISC

链接:https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26855

来源:MISC

链接:https://packetstormsecurity.com/files/162610/Microsoft-Exchange-2019-Unauthenticated-Email-Download.html

来源:MISC

链接:https://packetstormsecurity.com/files/162736/Microsoft-Exchange-ProxyLogon-Collector.html

来源:MISC

链接:https://packetstormsecurity.com/files/161938/Microsoft-Exchange-ProxyLogon-Remote-Code-Execution.html

来源:vigilance.fr

链接:https://vigilance.fr/vulnerability/Microsoft-Exchange-Server-multiple-vulnerabilities-34736

来源:www.exploit-db.com

链接:https://www.exploit-db.com/exploits/49895

来源:cxsecurity.com

链接:https://cxsecurity.com/issue/WLB-2021050123

来源:www.exploit-db.com

链接:https://www.exploit-db.com/exploits/49879

来源:nvd.nist.gov

链接:https://nvd.nist.gov/vuln/detail/CVE-2021-26855

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/162736/Microsoft-Exchange-ProxyLogon-Collector.html

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/161846/Microsoft-Exchange-2019-SSRF-Arbitrary-File-Write.html

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/161938/Microsoft-Exchange-ProxyLogon-Remote-Code-Execution.html

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/162610/Microsoft-Exchange-2019-Unauthenticated-Email-Download.html

受影响实体

    暂无


漏洞信息快速查询

相关漏洞

更多