Browse Definitions :

Askhat - stock.adobe.com

Everything you need to know about ProxyShell vulnerabilities

Organizations need to patch their Exchange Servers to protect against the ProxyShell exploit. Learn how to do that and more here.

ProxyShell is an attack chain that exploits three known vulnerabilities in Microsoft Exchange: CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207. By exploiting these vulnerabilities, attackers can perform remote code execution.

Microsoft has classified the ProxyShell vulnerabilities as critical, just as they do for any vulnerability that enables remote code execution. However, ProxyShell is especially critical for two reasons:

  1. Unlike some of the other remote code execution vulnerabilities discovered in Microsoft products over the years, ProxyShell is relatively easy to exploit.
  2. Security researchers discussed the exploit in detail at the 2021 Black Hat USA conference. This led to the exploit becoming well known in the hacker community.

There was an initial wave of attacks against Exchange Servers soon after details about ProxyShell became public. But even today, hackers are actively exploiting the ProxyShell vulnerabilities.

There are two main things that security researchers have observed hackers doing to affected systems.

1. Hackers create web shells

A web shell is essentially a command line interface that can be used to attack a vulnerable system. The ProxyShell exploits enable remote PowerShell sessions to be established with vulnerable Exchange Servers. There are several ways that attackers have used PowerShell to create web shells.

One of the best-known web shell exploits involves an attacker creating a draft e-mail message within an Exchange mailbox. This draft message contains a special attachment -- a file with an ASPX extension. Once this email message is created, the attacker uses the New-MailboxExportRequest cmdlet to export the mailbox contents to a PST file. This export process causes the message attachment to be decoded, allowing the attachment to be executed.

2. Hackers use ProxyShell as a tool to plant ransomware

In August and September 2021, there were a number of documented instances of attackers using the ProxyShell vulnerabilities to plant LockFile ransomware on unpatched Microsoft Exchange systems.  More recently, Babuk ransomware has been showing up on unpatched Exchange Servers. Squirrelwaffle has also been exploiting ProxyShell. Squirrelwaffle is malware that formulates malicious responses to legitimate email chains.

The most important thing to keep in mind about these types of ransomware and malware attacks is that they are not caused by a user who accidentally clicks on something that they shouldn't. Hackers are actively looking for unpatched Exchange Servers and planting malware and ransomware on those servers.

Learn about the decryptors Avast developed to recover data from LockFile, Babuk and AtomSilo ransomware variants.

Businesses affected

As of August 2021, more than 1,900 Exchange Servers were known to have been hacked. The types of organizations affected by ProxyShell attacks include building manufacturing, seafood processors, industrial machinery, auto repair shops, a small residential airport and more, according to a tweet from Kyle Hanslovan, CEO of Huntress Labs.

How to protect against ProxyShell vulnerabilities

The first thing that organizations need to do to protect themselves from ProxyShell vulnerabilities is patch their on-premises Microsoft Exchange Servers. Specifically, organizations need to deploy the latest cumulative update, plus either the May 2021 security updates or the July 2021 security updates. The cumulative update and the security update are both necessary to be protected. Exchange Server versions older than Exchange 2013 could be vulnerable regardless of whether or not they are patched.

In addition to patching any on-premises Exchange Servers, organizations also need to perform a comprehensive malware scan and security scan to determine if Exchange Servers have already been compromised. If an attacker has installed a web shell onto an Exchange Server, threat actors may be able to use that web shell to access systems even after they are patched.

Next Steps

ProxyShell leads to domain-wide ransomware attack

Dig Deeper on Security

SearchNetworking
  • cloud-native network function (CNF)

    A cloud-native network function (CNF) is a service that performs network duties in software, as opposed to purpose-built hardware.

  • microsegmentation

    Microsegmentation is a security technique that splits a network into definable zones and uses policies to dictate how data and ...

  • Wi-Fi 6E

    Wi-Fi 6E is one variant of the 802.11ax standard.

SearchSecurity
  • MICR (magnetic ink character recognition)

    MICR (magnetic ink character recognition) is a technology invented in the 1950s that's used to verify the legitimacy or ...

  • What is cybersecurity?

    Cybersecurity is the protection of internet-connected systems such as hardware, software and data from cyberthreats.

  • Android System WebView

    Android System WebView is a system component for the Android operating system (OS) that allows Android apps to display web ...

SearchCIO
  • privacy compliance

    Privacy compliance is a company's accordance with established personal information protection guidelines, specifications or ...

  • contingent workforce

    A contingent workforce is a labor pool whose members are hired by an organization on an on-demand basis.

  • product development (new product development -- NPD)

    Product development, also called new product management, is a series of steps that includes the conceptualization, design, ...

SearchHRSoftware
  • talent acquisition

    Talent acquisition is the strategic process employers use to analyze their long-term talent needs in the context of business ...

  • employee retention

    Employee retention is the organizational goal of keeping productive and talented workers and reducing turnover by fostering a ...

  • hybrid work model

    A hybrid work model is a workforce structure that includes employees who work remotely and those who work on site, in a company's...

SearchCustomerExperience
  • hockey stick growth

    Hockey stick growth is a growth pattern in a line chart that shows a sudden and extremely rapid growth after a long period of ...

  • Salesforce Trailhead

    Salesforce Trailhead is a series of online tutorials that coach beginner and intermediate developers who need to learn how to ...

  • Salesforce

    Salesforce, Inc. is a cloud computing and social enterprise software-as-a-service (SaaS) provider based in San Francisco.

Close