Browse Definitions :

Askhat - stock.adobe.com

Everything you need to know about ProxyShell vulnerabilities

Organizations need to patch their Exchange Servers to protect against the ProxyShell exploit. Learn how to do that and more here.

ProxyShell is an attack chain that exploits three known vulnerabilities in Microsoft Exchange: CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207. By exploiting these vulnerabilities, attackers can perform remote code execution.

Microsoft has classified the ProxyShell vulnerabilities as critical, just as they do for any vulnerability that enables remote code execution. However, ProxyShell is especially critical for two reasons:

  1. Unlike some of the other remote code execution vulnerabilities discovered in Microsoft products over the years, ProxyShell is relatively easy to exploit.
  2. Security researchers discussed the exploit in detail at the 2021 Black Hat USA conference. This led to the exploit becoming well known in the hacker community.

There was an initial wave of attacks against Exchange Servers soon after details about ProxyShell became public. But even today, hackers are actively exploiting the ProxyShell vulnerabilities.

There are two main things that security researchers have observed hackers doing to affected systems.

1. Hackers create web shells

A web shell is essentially a command line interface that can be used to attack a vulnerable system. The ProxyShell exploits enable remote PowerShell sessions to be established with vulnerable Exchange Servers. There are several ways that attackers have used PowerShell to create web shells.

One of the best-known web shell exploits involves an attacker creating a draft e-mail message within an Exchange mailbox. This draft message contains a special attachment -- a file with an ASPX extension. Once this email message is created, the attacker uses the New-MailboxExportRequest cmdlet to export the mailbox contents to a PST file. This export process causes the message attachment to be decoded, allowing the attachment to be executed.

2. Hackers use ProxyShell as a tool to plant ransomware

In August and September 2021, there were a number of documented instances of attackers using the ProxyShell vulnerabilities to plant LockFile ransomware on unpatched Microsoft Exchange systems.  More recently, Babuk ransomware has been showing up on unpatched Exchange Servers. Squirrelwaffle has also been exploiting ProxyShell. Squirrelwaffle is malware that formulates malicious responses to legitimate email chains.

The most important thing to keep in mind about these types of ransomware and malware attacks is that they are not caused by a user who accidentally clicks on something that they shouldn't. Hackers are actively looking for unpatched Exchange Servers and planting malware and ransomware on those servers.

Learn about the decryptors Avast developed to recover data from LockFile, Babuk and AtomSilo ransomware variants.

Businesses affected

As of August 2021, more than 1,900 Exchange Servers were known to have been hacked. The types of organizations affected by ProxyShell attacks include building manufacturing, seafood processors, industrial machinery, auto repair shops, a small residential airport and more, according to a tweet from Kyle Hanslovan, CEO of Huntress Labs.

How to protect against ProxyShell vulnerabilities

The first thing that organizations need to do to protect themselves from ProxyShell vulnerabilities is patch their on-premises Microsoft Exchange Servers. Specifically, organizations need to deploy the latest cumulative update, plus either the May 2021 security updates or the July 2021 security updates. The cumulative update and the security update are both necessary to be protected. Exchange Server versions older than Exchange 2013 could be vulnerable regardless of whether or not they are patched.

In addition to patching any on-premises Exchange Servers, organizations also need to perform a comprehensive malware scan and security scan to determine if Exchange Servers have already been compromised. If an attacker has installed a web shell onto an Exchange Server, threat actors may be able to use that web shell to access systems even after they are patched.

Next Steps

ProxyShell leads to domain-wide ransomware attack

Dig Deeper on Security

Networking
  • Telnet

    Telnet is a network protocol used to virtually access a computer and provide a two-way, collaborative and text-based ...

  • big-endian and little-endian

    The term endianness describes the order in which computer memory stores a sequence of bytes.

  • Address Resolution Protocol (ARP)

    Address Resolution Protocol (ARP) is a protocol that maps dynamic IP addresses to permanent physical machine addresses in a local...

Security
  • Mitre ATT&CK framework

    The Mitre ATT&CK (pronounced miter attack) framework is a free, globally accessible knowledge base that describes the latest ...

  • timing attack

    A timing attack is a type of side-channel attack that exploits the amount of time a computer process runs to gain knowledge about...

  • privileged identity management (PIM)

    Privileged identity management (PIM) is the monitoring and protection of superuser accounts that hold expanded access to an ...

CIO
HRSoftware
  • employee resource group (ERG)

    An employee resource group is a workplace club or more formally realized affinity group organized around a shared interest or ...

  • employee training and development

    Employee training and development is a set of activities and programs designed to enhance the knowledge, skills and abilities of ...

  • employee sentiment analysis

    Employee sentiment analysis is the use of natural language processing and other AI techniques to automatically analyze employee ...

Customer Experience
  • customer profiling

    Customer profiling is the detailed and systematic process of constructing a clear portrait of a company's ideal customer by ...

  • customer insight (consumer insight)

    Customer insight, also known as consumer insight, is the understanding and interpretation of customer data, behaviors and ...

  • buyer persona

    A buyer persona is a composite representation of a specific type of customer in a market segment.

Close