Website Security & Threat Management
Protecting against recently disclosed Microsoft Exchange Server vulnerabilities: CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065

Protecting against recently disclosed Microsoft Exchange Server vulnerabilities: CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065

3/7/2021 · Patrick R. Donahue, Gabriel Gabor

What this post added

This post details the deployment of Cloudflare WAF managed rules (specifically rule IDs 100179 and 100181 within the Cloudflare Specials ruleset) to protect against four specific Microsoft Exchange Server vulnerabilities (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065). It explains that these rules were deployed in 'Block' mode due to active exploitation in the wild and provides instructions for customers to enable or disable them. It also references server-side mitigation recommendations from Microsoft and details the technical chaining of the CVEs (SSRF, insecure deserialization, arbitrary file upload) that attackers exploit.

Read the original post ↗