ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

New Microsoft Exchange 'ProxyToken' Flaw Lets Attackers Reconfigure Mailboxes

criticalRansomware exploited in the wildimportance 60CVE-2021-33766

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-33766
Unauthenticated Information Disclosure (ProxyToken) in Microsoft Exchange Server

CVE-2021-33766, publicly known as 'ProxyToken', is an information disclosure vulnerability caused by an authentication bypass in the Exchange Control Panel (ECP) of Microsoft Exchange Server. An unauthenticated attacker sends specially crafted requests to the exposed ECP endpoint that abuse Exchange's default authentication-token handling in its proxy layer, so the backend treats the request as an authenticated session for another user's mailbox. The attacker gains access to victims' mailboxes — reading emails — and, as the related reporting notes, can reconfigure mailbox/server settings such as adding delegates or forwarding rules. Organizations running affected on-premises Exchange servers (Exchange Server 2016 and 2019 per Microsoft's advisory) with ECP/OWA exposed are affected; the cloud-hosted Exchange Online service is not. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-01-18 and EPSS estimates a 98.1% probability of exploitation within 30 days, though no public proof-of-concept is cataloged and ransomware use is unknown.

Do: Apply the July 2021 security updates — or any later cumulative or security update — for Exchange Server 2016/2019, per Microsoft's instructions and CISA's KEV required action. Until patched, limit internet exposure of ECP/OWA and review mailbox audit logs, delegate assignments, and inbox forwarding rules for signs of tampering, since ProxyToken has been used to read mail and reconfigure mailboxes.

7.398% KEV
  • microsoft exchange server on-premises Exchange Server 2016 and Exchange Server 2019 prior to the July 2021 Microsoft security updates
massseveral hundred thousand (order of 300,000–500,000) internet-exposed on-prem Exchange servers
Full article379 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananAug 31, 2021

Details have emerged about a now-patched security vulnerability impacting Microsoft Exchange Server that could be weaponized by an unauthenticated attacker to modify server configurations, thus leading to the disclosure of Personally Identifiable Information (PII).

The issue, tracked as CVE-2021-33766 (CVSS score: 7.3) and coined "ProxyToken," was discovered by Le Xuan Tuyen, a researcher at the Information Security Center of Vietnam Posts and Telecommunications Group (VNPT-ISC), and reported through the Zero-Day Initiative (ZDI) program in March 2021.

"With this vulnerability, an unauthenticated attacker can perform configuration actions on mailboxes belonging to arbitrary users," the ZDI said Monday. "As an illustration of the impact, this can be used to copy all emails addressed to a target and account and forward them to an account controlled by the attacker."

Microsoft addressed the issue as part of its Patch Tuesday updates for July 2021.

The security shortcoming resides in a feature called Delegated Authentication, which refers to a mechanism whereby the front-end website — the Outlook web access (OWA) client — passes authentication requests directly to the back-end when it detects the presence of a SecurityToken cookie.

However, since Exchange has to be specifically configured to use the feature and have the back-end carry out the checks, it leads to a scenario in which the module handling this delegation ("DelegatedAuthModule") isn't loaded under default configuration, culminating in a bypass as the back-end fails to authenticate incoming requests based on the SecurityToken cookie.

"The net result is that requests can sail through, without being subjected to authentication on either the front or back end," ZDI's Simon Zuckerbraun explained.

The disclosure adds to a growing list of Exchange Server vulnerabilities that have come to light this year, including ProxyLogon, ProxyOracle, and ProxyShell, which have been actively exploited by threat actors to take over unpatched servers, deploy malicious web shells and file-encrypting ransomware such as LockFile.

Troublingly, in-the-wild exploit attempts abusing ProxyToken have already been recorded as early as August 10, according to NCC Group security researcher Rich Warren, making it imperative that customers move quickly to apply the security updates from Microsoft.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/08/new-microsoft-exchange-proxytoken-flaw.html