CVE-2021-26858
Microsoft Exchange Server Remote Code Execution Vulnerability
Description
CVE-2021-26858 is a high-severity remote code execution vulnerability in Microsoft Exchange Server that is part of the ProxyLogon exploit chain. This vulnerability allows an authenticated attacker to write arbitrary files to the Exchange Server, which can be leveraged to execute malicious code. When chained with CVE-2021-26855 (the SSRF vulnerability that provides unauthenticated access), CVE-2021-26858 enables attackers to achieve complete server compromise without valid credentials. CISA has added CVE-2021-26858 to its Known Exploited Vulnerabilities catalog and included it in Emergency Directive 21-02, confirming active exploitation in the wild. With an EPSS score of 55.06% (98.0th percentile) and confirmed ransomware usage, this Exchange Server vulnerability requires immediate patching.
KEV Information
CVSS Score
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| microsoft | exchange server | 2010; 2013; 2016; 2019 |
Multiple CVSS Assessments
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References
Weakness Type
CWE-NVD-noinfo: Insufficient Information
The specific weakness type for CVE-2021-26858 has not been formally categorized by NVD beyond the general classification of a remote code execution vulnerability. The underlying mechanism involves an arbitrary file write capability in Exchange Server that allows an authenticated attacker to write files to any path on the server, which can then be used to deploy web shells or other malicious payloads.
Learn more: Microsoft Security Advisory for CVE-2021-26858
Impact Analysis
CVE-2021-26858 carries a CVSS 3.1 score of 7.8 (HIGH), reflecting a significant security threat to Microsoft Exchange Server environments. While the attack vector is classified as local with no authentication required, user interaction is needed for exploitation. Confidentiality (High): Successful exploitation can expose all data stored on the Exchange Server, including email contents, attachments, and configuration data. Integrity (High): The arbitrary file write capability allows an attacker to modify system files, deploy web shells, and alter server configurations. Availability (High): The attacker can disrupt Exchange Server operations by modifying or deleting critical files. The EPSS score of 55.06% indicates a high probability of active exploitation. When combined with CVE-2021-26855 as part of the ProxyLogon chain, the effective impact is significantly amplified, enabling unauthenticated remote code execution. Confirmed ransomware usage makes this vulnerability particularly dangerous for organizations running on-premises Exchange Server.
Exploit Maturity
CVE-2021-26858 is confirmed as actively exploited through its listing in the CISA Known Exploited Vulnerabilities catalog and inclusion in Emergency Directive 21-02. The EPSS score of 55.06% (98.0th percentile) indicates a high probability of exploitation activity. While no dedicated public exploit code with an "Exploit" tag was identified in NVD references specifically for CVE-2021-26858, the vulnerability is an integral part of the ProxyLogon exploit chain, for which comprehensive public exploit code exists. Ransomware usage is confirmed as "Known," with multiple threat actors leveraging the full ProxyLogon chain (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) for initial access and post-exploitation activities including web shell deployment and ransomware installation.
Remediation
- Apply vendor patches immediately as mandated by CISA Emergency Directive 21-02: Apply updates per vendor instructions. Microsoft released emergency out-of-band security updates in March 2021 for Exchange Server 2010, 2013, 2016, and 2019.
- Verify that all Microsoft Exchange Server instances (2010, 2013, 2016, 2019) have been updated to the latest patched cumulative updates. Run the Microsoft Exchange Server Health Checker tool (HealthChecker.ps1) to confirm patch status.
- Scan for indicators of compromise including web shells in Exchange Server directories, particularly aspx files in unexpected locations such as /aspnet_client/. Use Microsoft's MSERT tool and Test-ProxyLogon.ps1 script to detect exploitation artifacts.
- If any ProxyLogon chain indicators are detected, assume full server compromise. Conduct a comprehensive incident response including forensic preservation of Exchange logs, web shell identification and removal, credential rotation for all Exchange-accessible accounts, and assessment of lateral movement.
- Implement defense-in-depth measures including restricting external access to Exchange Server ports, deploying a web application firewall (WAF), enabling enhanced logging, and evaluating migration to Exchange Online to reduce on-premises attack surface.
Technical Details
CVE-2021-26858 is a remote code execution vulnerability in Microsoft Exchange Server that enables an authenticated attacker to write arbitrary files to the server. The vulnerability is part of the ProxyLogon exploit chain, where CVE-2021-26855 provides the initial unauthenticated SSRF access, and CVE-2021-26858 is used for post-authentication arbitrary file write operations. The CVSS vector string (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates a local attack vector with low complexity, no privileges required, but user interaction needed. The scope is unchanged, confining the direct impact to the vulnerable Exchange Server component. In practice, attackers exploit this vulnerability to write web shells (typically aspx files) to accessible IIS directories, establishing persistent remote access. The vulnerability affects Exchange Server versions 2010, 2013, 2016, and 2019, with Exchange Server 2010 being uniquely affected among the ProxyLogon chain vulnerabilities.
Frequently Asked Questions
Is CVE-2021-26858 being actively exploited?
Yes. CVE-2021-26858 is listed in the CISA Known Exploited Vulnerabilities catalog and is part of Emergency Directive 21-02. As a component of the ProxyLogon exploit chain, it has been widely exploited by multiple threat actors. Ransomware usage is confirmed, and the EPSS score of 55.06% (98.0th percentile) indicates a high exploitation probability.
What products are affected by CVE-2021-26858?
CVE-2021-26858 affects Microsoft Exchange Server versions 2010, 2013, 2016, and 2019. Notably, Exchange Server 2010 is affected by this specific vulnerability even though it is not affected by all other ProxyLogon chain CVEs. Exchange Online (Microsoft 365) is not affected.
How do I fix CVE-2021-26858?
Apply the emergency security updates released by Microsoft in March 2021. Run Microsoft's diagnostic tools (MSERT and Test-ProxyLogon.ps1) to check for indicators of compromise. If exploitation is detected, conduct a full incident response including web shell removal, credential rotation, and forensic analysis.
How severe is CVE-2021-26858?
CVE-2021-26858 has a CVSS 3.1 score of 7.8 (HIGH). While individually rated as high severity, its role in the ProxyLogon exploit chain effectively makes it critical, as it enables the file write operations necessary for web shell deployment and remote code execution when combined with the SSRF vulnerability CVE-2021-26855.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.