ProxyLogon
loresecurity
A 2021 chain of Microsoft Exchange flaws exploited widely in the wild.
ProxyLogon combined a server-side request forgery with further bugs to achieve unauthenticated remote code execution on on-premises Exchange servers. It was mass-exploited before patches were widely applied.
Also known as: ProxyLogon, CVE-2021-26855
Sources
- CVE-2021-26855 (2021)