References https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42321 https://nvd.nist.gov/vuln/detail/CVE-2021-42321 https://www.anquanke.com/post/id/261060 https://peterjson.medium.com/some-notes-about-microsoft-exchange-deserialization-rce-cve-2021-42321-110d04e8852 https://github.com/DarkSprings/CVE-2021-42321 https://gist.github.com/testanull/0188c1ae847f37a70fe536123d14f398 https://www.sentinelone.com/vulnerability-database/cve-2021-42321/ https://cloud.tencent.com/developer/article/1909373 https://rivers.chaitin.cn/blog/cq952590lnechd244j70 https://www.esentire.com/security-advisories/microsoft-exchange-vulnerability-cve-2021-42321
Related Vulnerabilities广联达OA /GB/LK/Document/DataExchange/DataExchange.ashx XML 外部实体注入漏洞PoCspringboot-httpexchanges: Detects Springboot HTTP Exchanges ActuatorPoCCVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2021-28481: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)飞企互联-FE企业运营管理平台 /docexchangeManage/checkGroupCode.jsp;.js SQL 注入漏洞PoCCVE-2008-1547: Microsoft OWA Exchange Server 2003 - 'redir.asp' Open RedirectionPoCCVE-2021-26855: Microsoft Exchange Server SSRF VulnerabilityPoCCVE-2021-31195: Microsoft Exchange Server - Cross-Site ScriptingPoCCVE-2021-34473: Exchange Server - Remote Code ExecutionPoCCVE-2021-41349: Microsoft Exchange Server Pre-Auth POST Based Cross-Site ScriptingPoCCVE-2021-26855: Microsoft Exchange Server Remote Code ExecutionPoCCVE-2021-41349: Microsoft Exchange Server Pre-Auth POST Based Reflected Cross-Site Scripting