非影资讯
面向安全从业者的中英双语安全研究与漏洞情报精选。

Pwn2Own 2021 Microsoft Exchange Exploit Chain

摘要

VULNERABILITY TITLE Microsoft Exchange Unauthenticated SSRF in Autodiscover frontend service combined with Authentication Bypass in Powershell Backend service and Arbitrary File Write in OAB backend service lead to Remote Code Execution VULNERABILITY SUMMARY The chains of 3 vulnerablity allows remote attackers to write a webshell and execute arbitrary code on
发布时间
收录时间

原文 ↗

相关内容

返回