#vulns.co
/
mcp by GKData.io

← Back to CVEs

CVE-2021-26855 — ProxyLogon - Exchange SSRF

Pre-auth SSRF in Exchange, chained to arbitrary file write for RCE. Basis of the ProxyLogon attack chain.

Tags: ssrf, exchange, proxylogon, chained

Product
Microsoft Exchange Server
Severity
critical (CVSS 9.8)
Published / added
2021-03
Signals
CISA KEV

References and evidence

← Back to CVEs