
3/7/2021 · Patrick R. Donahue, Gabriel Gabor
What this post added
This post details the deployment of Cloudflare WAF managed rules (specifically rule IDs 100179 and 100181 within the Cloudflare Specials ruleset) to protect against four specific Microsoft Exchange Server vulnerabilities (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065). It explains that these rules were deployed in 'Block' mode due to active exploitation in the wild and provides instructions for customers to enable or disable them. It also references server-side mitigation recommendations from Microsoft and details the technical chaining of the CVEs (SSRF, insecure deserialization, arbitrary file upload) that attackers exploit.