ProxyLogon
Chained CVE-2021-26855 and CVE-2021-27065
Theory
Practice
nmap -p80,443 --script="http-vuln-exchange.nse" $IP
443/tcp open https
|_http-vuln-proxylogon: (15.1.2176) Exchange 2016 potentially vulnerable, check latest security update is applied (Exchange 2016 CU18 or CU19 installed)#Method 1
PS> GCM exsetup |%{$_.Fileversioninfo}
#Method 2
PS> (Get-Command ExSetup.exe).FileVersionInfo.ProductVersion
ProductVersion FileVersion FileName
-------------- ----------- --------
15.02.0858.005 15.02.0858.005 C:\Program Files\Microsoft\Exchange Server\V15\bin\ExSetup.exeVersion
Vulnerable ProductVersion
Resources
Last updated