Potential CVE-2021-26857 Exploitation Attempt
Description
Detects possible successful exploitation for vulnerability described in CVE-2021-26857 by looking for | abnormal subprocesses spawning by Exchange Server's Unified Messaging service
Query · sigma
selection: ParentImage|endswith: \UMWorkerProcess.exe filter: Image|endswith: - wermgr.exe - WerFault.exe condition: selection and not filter
Known false positives
- Unknown