ProxyToken is an authentication bypass vulnerability in Microsoft Exchange Server tracked as CVE-2021-33766. The flaw affects the Exchange Control Panel (/ecp) request flow, where the front-end component delegates authentication to the back end when a non-empty SecurityToken cookie is present. In typical default configurations, the back-end delegated authentication module responsible for validating that token is not loaded, creating a logic gap in which specially crafted /ecp requests can bypass authentication. The issue also intersects with ECP canary handling, as an error response can disclose a valid canary token that can then be reused in subsequent requests. Successful exploitation allows an unauthenticated attacker to perform configuration actions against mailboxes belonging to arbitrary users, including creating mailbox rules that redirect or copy incoming email.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Bash proof-of-concept exploit (proxytoken.sh) and a README for CVE-2021-33766 (ProxyToken), an authentication bypass vulnerability in Microsoft Exchange Server. The script provides three main modes: 'check' (tests if a server is vulnerable using a valid victim email), 'newcheck' (tests for vulnerability without a valid user), and 'inboxrule' (creates a malicious inbox rule to redirect a victim's emails to an attacker-controlled address). The exploit works by sending crafted HTTP requests to Exchange Control Panel (ECP) endpoints, abusing the ProxyToken flaw to bypass authentication. The script is self-contained, requires only Bash and curl, and is intended for penetration testing and research. The README provides usage instructions, references, and a disclaimer. No hardcoded endpoints are present; the target server and emails are provided as arguments.
This repository provides an operational exploit for CVE-2021-33766 (ProxyToken), an authentication bypass vulnerability in Microsoft Exchange Server. The main script, 'proxytoken.py', is a Python tool that can both detect the presence of the ProxyToken vulnerability and exploit it to add a malicious email forwarding rule. The script supports single-target and batch modes (via 'url.txt'), and can be used to redirect a victim's emails to an attacker's address by abusing the Exchange Control Panel (ECP) endpoints. The exploit works by sending crafted HTTP(S) requests to specific ECP URLs, leveraging the authentication bypass to perform actions as an administrator or as a targeted user. The repository includes a README (in Chinese) with usage instructions and references, the main exploit script, and a sample URL list file. The exploit is operational, requiring only Python and network access to the target Exchange server.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.