
CVE-2021-34473 ProxyShell: Pre-Auth Exchange RCE Chain
CVE-2021-34473 is the first link in the ProxyShell exploit chain, three Microsoft Exchange Server vulnerabilities that together enable unauthenticated remote code execution. Chained with CVE-2021-34523 and CVE-2021-31207, an attacker can reach Exchange's backend PowerShell endpoint without credentials, impersonate any mailbox user, and write arbitrary files to Exchange's web root to deploy a web shell.
