Security News > 2021 > August > Microsoft Breaks Silence on Barrage of ProxyShell Attacks

Microsoft Breaks Silence on Barrage of ProxyShell Attacks
2021-08-26 12:39

Microsoft has broken its silence on the recent barrage of attacks on several ProxyShell vulnerabilities in that were highlighted by a researcher at Black Hat earlier this month.

"Please update now!"Customers that have installed the May 2021 security updates or the July 2021 security updates on their Exchange servers are protected from these vulnerabilities, as are Exchange Online customers so long as they ensure that all hybrid Exchange servers are updated, the company wrote.

The three vulnerabilities enable an adversary to trigger remote code execution on Microsoft Exchange servers.

"Any Exchange servers that are not on a supported CU and the latest available SU are vulnerable to ProxyShell and other attacks that leverage older vulnerabilities."

Security researchers at Huntress also reported seeing ProxyShell vulnerabilities being actively exploited throughout the month of August to install backdoor access once the ProxyShell exploit code was published on Aug. 6.

Starting last Friday, Huntress reported a "Surge" in attacks after finding 140 webshells launched against 1,900 unpatched Exchange servers.


News URL

https://threatpost.com/microsoft-barrage-proxyshell-attacks/168943/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 381 51 1408 2910 175 4544