漏洞描述
Microsoft Exchange Server contains a remote code execution caused by improper input validation in the server component, letting remote attackers execute arbitrary code, exploit requires network access to the server.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
sec.vnpt.vnhttps://sec.vnpt.vn/2021/04/microsoft-exchange-from-deserialization-to-post-auth-rce-cve-2021-28482↗hitcon.orghttps://hitcon.org/2021/agenda/279d7810-e619-4dc3-9113-b11bad5277ec/The%20Proxy%20Era%20of%20Microsoft%20Exchange%20Server.pdf↗www.youtube.comhttps://www.youtube.com/watch?v=vn4niT9XEIM↗msrc.microsoft.comhttps://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2021-28481↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/cve-2021-28481↗