Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-34473 PoC — Microsoft Exchange Server Remote Code Execution Vulnerability

Source
Associated Vulnerability
Title:Microsoft Exchange Server Remote Code Execution Vulnerability (CVE-2021-34473)
Description:Microsoft Exchange Server Remote Code Execution Vulnerability
Description
Scanner for CVE-2021-34473, ProxyShell, A Microsoft Exchange On-premise Vulnerability
Readme
# CVE-2021-34473-scanner
Scanner for CVE-2021-34473, ProxyShell, A Microsoft Exchange On-premise Vulnerability

To test machines one by one, use scanner-CVE-2021-34473.bat:

scanner-CVE-2021-34473.bat mail.exemple.fr 

To test multiple machines at once, use mass-scanner and add ip/FQDN to check, one by line, in servers-to-check.txt:

mass-scanner-CVE-2021-34473.bat


Remediation depending on Exchange version:

Exchange 2019 CU10
Download
15.2.922.13
KB5004780
https://www.microsoft.com/en-us/download/details.aspx?id=103309

Exchange 2019 CU9
Download
15.2.858.15
KB5004780
https://www.microsoft.com/en-us/download/details.aspx?id=103308

Exchange 2016 CU21
Download
15.1.2308.14
KB5004779
https://www.microsoft.com/en-us/download/details.aspx?id=103310

Exchange 2016 CU20
Download
15.1.2242.12
KB5004779
https://www.microsoft.com/en-us/download/details.aspx?id=103310

Exchange 2013 CU23
Download
15.0.1497.23
KB5004778
https://www.microsoft.com/en-us/download/details.aspx?id=103312
File Snapshot

[4.0K] /data/pocs/6ebab760607f87be7f86a04b5968748b6ca09cae ├── [ 34K] LICENSE ├── [ 375] mass-scanner-CVE-2021-34473.bat ├── [ 990] README.md ├── [ 448] scanner-CVE-2021-34473.bat └── [ 42] servers-to-check.txt 0 directories, 5 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →