ProxyToken vulnerability can modify Exchange server configs
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-33766 | Unauthenticated Information Disclosure (ProxyToken) in Microsoft Exchange Server CVE-2021-33766, publicly known as 'ProxyToken', is an information disclosure vulnerability caused by an authentication bypass in the Exchange Control Panel (ECP) of Microsoft Exchange Server. An unauthenticated attacker sends specially crafted requests to the exposed ECP endpoint that abuse Exchange's default authentication-token handling in its proxy layer, so the backend treats the request as an authenticated session for another user's mailbox. The attacker gains access to victims' mailboxes — reading emails — and, as the related reporting notes, can reconfigure mailbox/server settings such as adding delegates or forwarding rules. Organizations running affected on-premises Exchange servers (Exchange Server 2016 and 2019 per Microsoft's advisory) with ECP/OWA exposed are affected; the cloud-hosted Exchange Online service is not. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-01-18 and EPSS estimates a 98.1% probability of exploitation within 30 days, though no public proof-of-concept is cataloged and ransomware use is unknown. Do: Apply the July 2021 security updates — or any later cumulative or security update — for Exchange Server 2016/2019, per Microsoft's instructions and CISA's KEV required action. Until patched, limit internet exposure of ECP/OWA and review mailbox audit logs, delegate assignments, and inbox forwarding rules for signs of tampering, since ProxyToken has been used to read mail and reconfigure mailboxes. | 7.3 | 98% | KEV |
| massseveral hundred thousand (order of 300,000–500,000) internet-exposed on-prem Exchange servers |
Full article288 words · extracted from therecord.media · click to collapse
If the ProxyShell vulnerability wasn't enough of a good reason for system administrators to apply the July 2020 Microsoft Exchange security updates, there is a second major security bug in those updates that can allow for devastating hacks. Nicknamed ProxyToken, the vulnerability allows a remote attacker to bypass authentication and make changes to an Exchange email server's backend configuration. Discovered by Le Xuan Tuyen, a Vietnamese security researcher with VNPT ISC, the ProxyToken vulnerability could be used to surreptitiously add an email forwarding rule to a user's mailbox so that all emails addressed to the victim will also be sent to an account controlled by the attacker. Reported through the Zero-Day Initiative program, Le says the vulnerability exists because of two issues in the Exchange code: By combining the two, Le says a ProxyToken attack is possible and that attackers can easily make requests to any part of the Exchange backend, including its users' control panels and settings. Reported in April, the bug was fixed with the July 2021 Patch Tuesday security updates under the CVE-2021-33766 identifier. Since details about this attack are expected to go live later today on the Zero-Day Initiative blog, server owners should expect threat actors to weaponize this vector. This is exactly what happened last month when attacks against Exchange servers took off after details about the ProxyShell vulnerability were published online. Those attacks quickly escalated in a matter of days and today, a new ransomware operation known as LockFile is abusing Exchange servers to encrypt corporate networks.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/proxytoken-vulnerability-can-modify-exchange-server-configs