Sploitus

Exploit for ProxyLogon

kitploit · 2026-08-25

Exploit Code

MARKDOWN38 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-RICKGEEX-PROXYLOGON
# ProxyLogon

ProxyLogon 是 CVE-2021-26855 的正式通用名称,这是一个 Microsoft Exchange Server 上的漏洞,允许攻击者绕过身份验证并冒充管理员。我们还将该漏洞与另一个认证后的任意文件写入漏洞 CVE-2021-27065 结合,以实现代码执行。(来源:proxylogon.com)

## 免责声明

本 GitHub 仓库提供的信息仅供教育目的。本 GitHub 上的所有信息均以善意提供,但我不对任何信息的准确性、充分性、有效性、可靠性、可用性或完整性作出任何明示或暗示的陈述或保证。

## 开始使用

### 要求

  * 此脚本需要 Python3 和 urllib 库



如果你想要测试该漏洞,请仅在你的(非生产)系统上进行

root@kitploit:~
    
    
    python ProxyLogon.py <hostname> <email>
    

## 截图

![ProxyLogon](https://assets.kitploit.com/production/public/readmes/20142/ef41ca047b7c00109fa1e964ecc7b0de070a8706eb59392e69951d816663642c.png)

## 缓解措施

### 更新

#### 累积更新

以下安全更新适用于以下 Microsoft Exchange Server 版本:

  * Microsoft Exchange Server 2013 Cumulative Update 23