ProxyShell
loresecurity
A 2021 Exchange exploit chain related to ProxyLogon.
ProxyShell chained three Exchange vulnerabilities to reach remote code execution, and like ProxyLogon it was heavily exploited by multiple threat actors. Together they made Exchange patching an urgent priority that year.
ProxyShell was a second chain of Exchange vulnerabilities disclosed after ProxyLogon, following the same pattern of combining several flaws into unauthenticated remote code execution, and exploited heavily by ransomware operators against organizations that had patched the first chain and not the second.
The pattern it demonstrates is worth naming: a product that produces one serious vulnerability chain frequently produces another, because the underlying architecture and the assumptions that allowed the first are still present. Attackers who invested in understanding a codebase for the first campaign are also the best-placed people to find the next issue, so research concentrates rather than disperses.
The strategic consequence for defenders is that a single patch is not a resolution when the same component keeps producing exploitable chains. That reasoning is what moved many organizations off on-premises Exchange entirely, which is a legitimate response and a form of risk transfer rather than risk elimination, since the hosted alternative concentrates the same risk somewhere with better staffing and a much larger blast radius when it does fail.
Also known as: ProxyShell, CVE-2021-34473
Sources
- CVE-2021-34473 (2021)