diff --git a/Microsoft/Exchange/CVE-2021-34473/Microsoft_Exchange_Server_Remote_Code_Execution_Vulnerability_CVE-2021-34473.gif b/Microsoft/Exchange/CVE-2021-34473/Microsoft_Exchange_Server_Remote_Code_Execution_Vulnerability_CVE-2021-34473.gif new file mode 100644 index 0000000..30d5f05 Binary files /dev/null and b/Microsoft/Exchange/CVE-2021-34473/Microsoft_Exchange_Server_Remote_Code_Execution_Vulnerability_CVE-2021-34473.gif differ diff --git a/Microsoft/Exchange/CVE-2021-34473/README.md b/Microsoft/Exchange/CVE-2021-34473/README.md new file mode 100644 index 0000000..ca30e8d --- /dev/null +++ b/Microsoft/Exchange/CVE-2021-34473/README.md @@ -0,0 +1,32 @@ +# Microsoft Exchange Server Remote Code Execution Vulnerability (CVE-2021-34473) + +Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31196, CVE-2021-31206. + +**[FOFA](https://fofa.so/result?qbase64=YXBwPSJNaWNyb3NvZnQtRXhjaGFuZ2UtMjAxMyJ8fGFwcD0iTWljcm9zb2Z0LUV4Y2hhbmdlLVNlcnZlci0yMDEzLUNVMjEifHxhcHA9Ik1pY3Jvc29mdC1FeGNoYW5nZS1TZXJ2ZXItMjAxMy1DVTE3Inx8YXBwPSJNaWNyb3NvZnQtRXhjaGFuZ2UtU2VydmVyLTIwMTMtQ1UyMyJ8fGFwcD0iTWljcm9zb2Z0LUV4Y2hhbmdlLVNlcnZlci0yMDEzLUNVMTMifHxhcHA9Ik1pY3Jvc29mdC1FeGNoYW5nZS1TZXJ2ZXItMjAxMy1DVTIyInx8YXBwPSJNaWNyb3NvZnQtRXhjaGFuZ2UtU2VydmVyLTIwMTMtQ1UxMSJ8fGFwcD0iTWljcm9zb2Z0LUV4Y2hhbmdlLVNlcnZlci0yMDEzLUNVMiJ8fGFwcD0iTWljcm9zb2Z0LUV4Y2hhbmdlLVNlcnZlci0yMDEzLUNVMTYifHxhcHA9Ik1pY3Jvc29mdC1FeGNoYW5nZS1TZXJ2ZXItMjAxMy1DVTE5Inx8YXBwPSJNaWNyb3NvZnQtRXhjaGFuZ2UtU2VydmVyLTIwMTMtQ1UzInx8YXBwPSJNaWNyb3NvZnQtRXhjaGFuZ2UtU2VydmVyLTIwMTMtQ1UxOCJ8fGFwcD0iTWljcm9zb2Z0LUV4Y2hhbmdlLVNlcnZlci0yMDEzLUNVNSJ8fGFwcD0iTWljcm9zb2Z0LUV4Y2hhbmdlLVNlcnZlci0yMDEzLUNVMjAifHxhcHA9Ik1pY3Jvc29mdC1FeGNoYW5nZS1TZXJ2ZXItMjAxMy1DVTEyInx8YXBwPSJNaWNyb3NvZnQtRXhjaGFuZ2UtU2VydmVyLTIwMTMtQ1UxNSJ8fGFwcD0iTWljcm9zb2Z0LUV4Y2hhbmdlLVNlcnZlci0yMDEzLUNVMTAifHxhcHA9Ik1pY3Jvc29mdC1FeGNoYW5nZS1TZXJ2ZXItMjAxMy1DVTkifHxhcHA9Ik1pY3Jvc29mdC1FeGNoYW5nZS1TZXJ2ZXItMjAxMy1DVTYifHxhcHA9Ik1pY3Jvc29mdC1FeGNoYW5nZS1TZXJ2ZXItMjAxMy1DVTcifHxhcHA9Ik1pY3Jvc29mdC1FeGNoYW5nZS1TZXJ2ZXItMjAxMy1DVTEifHxhcHA9Ik1pY3Jvc29mdC1FeGNoYW5nZS1TZXJ2ZXItMjAxMy1DVTE0Inx8YXBwPSJNaWNyb3NvZnQtRXhjaGFuZ2UtU2VydmVyLTIwMTMtQ1U4Inx8YXBwPSJNaWNyb3NvZnQtRXhjaGFuZ2UtU2VydmVyLTIwMTMtUlRNInx8YXBwPSJNaWNyb3NvZnQtRXhjaGFuZ2UtU2VydmVyLTIwMTMtU1AxInx8YXBwPSJNaWNyb3NvZnQtRXhjaGFuZ2UtMjAxMyI%3D) query rule**: + +```json +microsoft exchange 2013: + +app="Microsoft-Exchange-2013"||app="Microsoft-Exchange-Server-2013-CU21"||app="Microsoft-Exchange-Server-2013-CU17"||app="Microsoft-Exchange-Server-2013-CU23"||app="Microsoft-Exchange-Server-2013-CU13"||app="Microsoft-Exchange-Server-2013-CU22"||app="Microsoft-Exchange-Server-2013-CU11"||app="Microsoft-Exchange-Server-2013-CU2"||app="Microsoft-Exchange-Server-2013-CU16"||app="Microsoft-Exchange-Server-2013-CU19"||app="Microsoft-Exchange-Server-2013-CU3"||app="Microsoft-Exchange-Server-2013-CU18"||app="Microsoft-Exchange-Server-2013-CU5"||app="Microsoft-Exchange-Server-2013-CU20"||app="Microsoft-Exchange-Server-2013-CU12"||app="Microsoft-Exchange-Server-2013-CU15"||app="Microsoft-Exchange-Server-2013-CU10"||app="Microsoft-Exchange-Server-2013-CU9"||app="Microsoft-Exchange-Server-2013-CU6"||app="Microsoft-Exchange-Server-2013-CU7"||app="Microsoft-Exchange-Server-2013-CU1"||app="Microsoft-Exchange-Server-2013-CU14"||app="Microsoft-Exchange-Server-2013-CU8"||app="Microsoft-Exchange-Server-2013-RTM"||app="Microsoft-Exchange-Server-2013-SP1"||app="Microsoft-Exchange-2013" +``` + +```json +microsoft exchange 2016: +app="Microsoft-Exchange-Server-2016-CU19"||app="Microsoft-Exchange-Server-2016-CU3"||app="Microsoft-Exchange-Server-2016-CU12"||app="Microsoft-Exchange-Server-2016-RTM"||app="Microsoft-Exchange-Server-2016-CU7"||app="Microsoft-Exchange-Server-2016-CU17"||app="Microsoft-Exchange-Server-2016-CU2"||app="Microsoft-Exchange-Server-2016-CU1"||app="Microsoft-Exchange-Server-2016-CU14"||app="Microsoft-Exchange-Server-2016-CU5"||app="Microsoft-Exchange-Server-2016-CU11"||app="Microsoft-Exchange-Server-2016-CU9"||app="Microsoft-Exchange-Server-2016-CU16"||app="Microsoft-Exchange-Server-2016-CU10"||app="Microsoft-Exchange-Server-2016-CU6"||app="Microsoft-Exchange-Server-2016-CU13"||app="Microsoft-Exchange-Server-2016-CU18"||app="Microsoft-Exchange-Server-2016-CU8"||app="Microsoft-Exchange-Server-2016-CU4"||app="Microsoft-Exchange-2016-POP3-server" +``` + +```json +microsoft exchange 2019: +app="Microsoft-Exchange-Server-2019-CU5"||app="Microsoft-Exchange-Server-2019-CU3"||app="Microsoft-Exchange-Server-2019-Preview"||app="Microsoft-Exchange-Server-2019-CU8"||app="Microsoft-Exchange-Server-2019-CU1"||app="Microsoft-Exchange-Server-2019-CU7"||app="Microsoft-Exchange-Server-2019-CU2"||app="Microsoft-Exchange-Server-2019-CU6"||app="Microsoft-Exchange-Server-2019-RTM"||app="Microsoft-Exchange-Server-2019-CU4" +``` + +```json +microsoft exchange 2010: +app="Microsoft-Exchange-2010-POP3-server-version-03.1"||app="Microsoft-Exchange-Server-2010" +``` + + + +# Demo + +![](Microsoft_Exchange_Server_Remote_Code_Execution_Vulnerability_CVE-2021-34473.gif) \ No newline at end of file