GossiTheDog / scanning

158 stars 59 forks source link

Exchange 2013 Version check #5

Open lksmrl opened 3 years ago

lksmrl commented 3 years ago

Line 64 -> 71 Server version is at most 15.0.1497, does this mean that 2013s are still at risk even after the patch? Compare Microsoft: https://docs.microsoft.com/de-de/exchange/new-features/build-numbers-and-release-dates?view=exchserver-2019#exchange-server-2013

Cheers

lukastribus commented 3 years ago

"Potentially vulnerable" means that this script cannot determine anything (because it's just looking at the version, which is not saying anything). Also see #4

I strongly suggest people use Microsoft's nmap script instead, which does proper detection:

https://github.com/microsoft/CSS-Exchange/blob/main/Security/src/http-vuln-cve2021-26855.nse