Browse Definitions :

Askhat - stock.adobe.com

Everything you need to know about ProxyShell vulnerabilities

Organizations need to patch their Exchange Servers to protect against the ProxyShell exploit. Learn how to do that and more here.

ProxyShell is an attack chain that exploits three known vulnerabilities in Microsoft Exchange: CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207. By exploiting these vulnerabilities, attackers can perform remote code execution.

Microsoft has classified the ProxyShell vulnerabilities as critical, just as they do for any vulnerability that enables remote code execution. However, ProxyShell is especially critical for two reasons:

  1. Unlike some of the other remote code execution vulnerabilities discovered in Microsoft products over the years, ProxyShell is relatively easy to exploit.
  2. Security researchers discussed the exploit in detail at the 2021 Black Hat USA conference. This led to the exploit becoming well known in the hacker community.

There was an initial wave of attacks against Exchange Servers soon after details about ProxyShell became public. But even today, hackers are actively exploiting the ProxyShell vulnerabilities.

There are two main things that security researchers have observed hackers doing to affected systems.

1. Hackers create web shells

A web shell is essentially a command line interface that can be used to attack a vulnerable system. The ProxyShell exploits enable remote PowerShell sessions to be established with vulnerable Exchange Servers. There are several ways that attackers have used PowerShell to create web shells.

One of the best-known web shell exploits involves an attacker creating a draft e-mail message within an Exchange mailbox. This draft message contains a special attachment -- a file with an ASPX extension. Once this email message is created, the attacker uses the New-MailboxExportRequest cmdlet to export the mailbox contents to a PST file. This export process causes the message attachment to be decoded, allowing the attachment to be executed.

2. Hackers use ProxyShell as a tool to plant ransomware

In August and September 2021, there were a number of documented instances of attackers using the ProxyShell vulnerabilities to plant LockFile ransomware on unpatched Microsoft Exchange systems.  More recently, Babuk ransomware has been showing up on unpatched Exchange Servers. Squirrelwaffle has also been exploiting ProxyShell. Squirrelwaffle is malware that formulates malicious responses to legitimate email chains.

The most important thing to keep in mind about these types of ransomware and malware attacks is that they are not caused by a user who accidentally clicks on something that they shouldn't. Hackers are actively looking for unpatched Exchange Servers and planting malware and ransomware on those servers.

Learn about the decryptors Avast developed to recover data from LockFile, Babuk and AtomSilo ransomware variants.

Businesses affected

As of August 2021, more than 1,900 Exchange Servers were known to have been hacked. The types of organizations affected by ProxyShell attacks include building manufacturing, seafood processors, industrial machinery, auto repair shops, a small residential airport and more, according to a tweet from Kyle Hanslovan, CEO of Huntress Labs.

How to protect against ProxyShell vulnerabilities

The first thing that organizations need to do to protect themselves from ProxyShell vulnerabilities is patch their on-premises Microsoft Exchange Servers. Specifically, organizations need to deploy the latest cumulative update, plus either the May 2021 security updates or the July 2021 security updates. The cumulative update and the security update are both necessary to be protected. Exchange Server versions older than Exchange 2013 could be vulnerable regardless of whether or not they are patched.

In addition to patching any on-premises Exchange Servers, organizations also need to perform a comprehensive malware scan and security scan to determine if Exchange Servers have already been compromised. If an attacker has installed a web shell onto an Exchange Server, threat actors may be able to use that web shell to access systems even after they are patched.

Next Steps

ProxyShell leads to domain-wide ransomware attack

Dig Deeper on Security

SearchNetworking
SearchSecurity
  • man in the browser (MitB)

    Man in the browser (MitB) is a security attack where the perpetrator installs a Trojan horse on the victim's computer that is ...

  • Patch Tuesday

    Patch Tuesday is the unofficial name of Microsoft's monthly scheduled release of security fixes for the Windows operating system ...

  • parameter tampering

    Parameter tampering is a type of web-based cyber attack in which certain parameters in a URL are changed without a user's ...

SearchCIO
  • chief procurement officer (CPO)

    The chief procurement officer, or CPO, leads an organization's procurement department and oversees the acquisitions of goods and ...

  • Lean Six Sigma

    Lean Six Sigma is a data-driven approach to improving efficiency, customer satisfaction and profits.

  • change management

    Change management is a systematic approach to dealing with the transition or transformation of an organization's goals, processes...

SearchHRSoftware
SearchCustomerExperience
  • clickstream data (clickstream analytics)

    Clickstream data and clickstream analytics are the processes involved in collecting, analyzing and reporting aggregate data about...

  • neuromarketing

    Neuromarketing is the study of how people's brains respond to advertising and other brand-related messages by scientifically ...

  • contextual marketing

    Contextual marketing is an online marketing strategy model in which people are served with targeted advertising based on their ...

Close