Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Pwn2Own 2021 Microsoft Exchange Exploit Chain

Summary

VULNERABILITY TITLE Microsoft Exchange Unauthenticated SSRF in Autodiscover frontend service combined with Authentication Bypass in Powershell Backend service and Arbitrary File Write in OAB backend service lead to Remote Code Execution VULNERABILITY SUMMARY The chains of 3 vulnerablity allows remote attackers to write a webshell and execute arbitrary code on
Published
Collected

original ↗

Related coverage

back