[{"title":"Microsoft Exchange Proxylogon Remote Code Execution Vulnerability Exploit","body":"This module first exploits a server side request forgery vulnerability present in Microsoft.Exchange.HttpProxy of Microsoft Exchange Server to bypass authentication. Then an arbitrary file write vulnerability present in WriteFileActivity of Microsoft.Exchange.Management.ControlPanel.DIService is used to deploy a .aspx file and execute commands. The deployed agent will run with the SYSTEM privileges.","created":"\u003Ctime datetime=\u00222021-06-03T00:00:00-05:00\u0022 class=\u0022datetime\u0022\u003EJune 3, 2021\u003C\/time\u003E\n","field_cve_link":"\u003Ca href=\u0022https:\/\/www.cve.org\/CVERecord?id=CVE-2021-26855\u0022 target=\u0022_blank\u0022\u003ECVE-2021-26855\u003C\/a\u003E, \u003Ca href=\u0022https:\/\/www.cve.org\/CVERecord?id=CVE-2021-27065\u0022 target=\u0022_blank\u0022\u003ECVE-2021-27065\u003C\/a\u003E","field_exploit_platform":"Windows","field_exploit_type":"Exploits \/ Remote Code Execution","field_product_name":"Impact"}]