'; } else{ echo ''; } echo 'Hillstone Networks'; } elseif ($_SERVER[HTTP_HOST] == "update1.huaantech.com.cn") { echo ''; echo 'huaantech'; } elseif ($_SERVER[HTTP_HOST] == "update1.dcnetworks.com.cn") { echo ''; echo 'dcnetworks'; } elseif ($_SERVER[HTTP_HOST] == "update1.w-ibeda.com") { if (false===strpos($_SERVER[REQUEST_URI],"/en/")) echo ''; else echo ''; echo 'w-ibeda'; } elseif ($_SERVER[HTTP_HOST] == "update1.hp-telecom.com") { echo ''; echo 'hp-telecom'; } elseif ($_SERVER[HTTP_HOST] == "update1.maipu.com") { echo ''; echo 'Maipu'; } elseif ($_SERVER[HTTP_HOST] == "update1.ncurity.com") { echo ''; echo 'Ncurity'; } elseif ($_SERVER[HTTP_HOST] == "update1.socusnetwork.com") { echo ''; echo 'Socusnetwork'; } else{ echo ''; echo 'Hillstone Networks'; } ?>
 
   
 

RULE(RULE ID:339610)

Rule General Information
Release Date: 2025-11-12
Rule Name: Exchange Arbitrary File Write Vulnerability (CVE-2021-27065)
Severity:
CVE ID:
Rule Protection Details
Description: This event indicates that an attempt has been made to exploit CVE-2021-27065, a post-authentication arbitrary file-write flaw in Microsoft Exchange Server. Attackers who have already obtained valid administrator credentials can upload a malicious file—commonly an .aspx web shell—into an accessible path under the IIS web root. Once the file is written, it can be invoked remotely through an HTTP request, granting the adversary persistent, privileged code execution on the mail server. Because Exchange typically runs with SYSTEM authority, successful exploitation leads to full domain compromise, allowing the attacker to read or modify any mailbox, harvest credentials, move laterally inside the network, or deploy ransomware across the organization. The vulnerability was chained with CVE-2021-26855 (ProxyLogon) in widespread campaigns, but it can also be exploited independently by any adversary who has hijacked or misused an Exchange admin account.
Impact: An attacker can write arbitrary files by constructing a specially crafted request, thus realizing unauthorized arbitrary file upload, which can eventually cause remote code execution.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.