• Platformchevron right
  • Solutionschevron right
  • Modern NDRchevron right
  • Resourceschevron right
  • Companychevron right

DETECTION OVERVIEW

ProxyLogon Exploit - [Multiple CVEs]

Risk Factors

Unpatched Microsoft Exchange Servers exposed to the internet can be exploited by unauthenticated attackers. Multiple Exchange Server vulnerabilities that lead to remote code execution (RCE) are well known. Public code helps attackers exploit these vulnerabilities, enabling them to steal sensitive email communications or install malware to facilitate additional attacks.

Kill Chain

Exploitation

Risk Score

87

Detection diagram
Next in Exploitation: ProxyShell and ProxyNOTShell Exploits - [Multiple CVEs]

Attack Background

Microsoft Exchange Server front-end architecture, which acts as a proxy for the back-end server, includes a vulnerability that can be linked to other Exchange Server vulnerabilities in an attack chain. The first vulnerability in the chain, CVE-2021-26855, enables server-side request forgery (SSRF) attacks. In an SSRF attack, the attacker sends an SSRF request (an HTTP request with a forged malicious cookie) to the front-end Internet Information Services (IIS) component of the Exchange Server. This IIS component accepts the malicious cookie, forwarding the request to the back-end IIS component for processing. The SSRF request results in the exposure of sensitive Exchange Server information, such as an administrator security identifier (SID). With a SID, the attacker can bypass authentication with another SSRF request that allows the attacker to log into the back-end server as an administrator. After logging in, the attacker exploits additional vulnerabilities in the attack chain (CVE-2021-26858 and CVE-2021-27065) to write files to the Exchange server and achieve remote code execution (RCE).

Mitigation Options

Install relevant patches for affected versions

If unable to patch, make the recommended changes provided in Microsoft Exchange Server Vulnerabilities Mitigations (see the link below)

MITRE ATT&CK ID

What else can RevealX do for you?