ProxyLogon
loresecurity
A 2021 chain of Microsoft Exchange flaws exploited widely in the wild.
ProxyLogon combined a server-side request forgery with further bugs to achieve unauthenticated remote code execution on on-premises Exchange servers. It was mass-exploited before patches were widely applied.
ProxyLogon was a chain of vulnerabilities in on-premises Microsoft Exchange, combining a server-side request forgery with a file write to achieve unauthenticated remote code execution. Mass exploitation began before most organizations had patched, and a very large number of Exchange servers worldwide were compromised.
What made it consequential is who runs Exchange on premises. By that point most large enterprises had moved to hosted mail, so the affected population skewed toward smaller organizations, local government, schools and businesses without dedicated security staff, precisely the population least able to detect a compromise or respond to one. The victims were selected by the technology rather than by the attacker.
The aftermath included a genuinely unusual event: a court-authorized operation in which the FBI removed web shells from compromised servers without the owners' involvement. That was legally novel, ethically contested and a reasonable response to the fact that thousands of organizations did not know they were compromised. It is worth knowing about, because it set a precedent for what governments may do about vulnerable infrastructure that its owners cannot manage.
Also known as: ProxyLogon, CVE-2021-26855
Sources
- CVE-2021-26855 (2021)