Files
splunk-security_content/docs/_stories/proxyshell.md
T
2021-09-22 14:56:08 -04:00

3.3 KiB

title, last_modified_at, toc, tags
title last_modified_at toc tags
ProxyShell 2021-08-24 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Endpoint

Try in Splunk Cloud{: .btn .btn--success}

Description

ProxyShell is a chain of exploits targeting on-premise Microsoft Exchange Server - CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207.

  • ID: 413bb68e-04e2-11ec-a835-acde48001122
  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel: Endpoint
  • Last Updated: 2021-08-24
  • Author: Michael Haag, Teoderick Contreras, Mauricio Velazco, Splunk

Narrative

During Pwn2Own April 2021, a security researcher demonstrated an attack chain targeting on-premise Microsoft Exchange Server. August 5th, the same researcher publicly released further details and demonstrated the attack chain. \

  1. CVE-2021-34473 - Pre-auth path confusion leads to ACL Bypass (Patched in April by KB5001779) \
  2. CVE-2021-34523 - Elevation of privilege on Exchange PowerShell backend (Patched in April by KB5001779) \
  3. CVE-2021-31207 - Post-auth Arbitrary-File-Write leads to RCE (Patched in May by KB5003435)
    Upon successful exploitation, the remote attacker will have SYSTEM privileges on the Exchange Server. In addition to remote access/execution, the adversary may be able to run Exchange PowerShell Cmdlets to perform further actions.

Detections

Name Technique Type
Detect Exchange Web Shell Web Shell, Exploit Public-Facing Application, PowerShell TTP
Exchange PowerShell Abuse via SSRF Exploit Public-Facing Application TTP
Exchange PowerShell Module Usage PowerShell TTP
W3WP Spawning Shell Web Shell TTP

Reference

source | version: 1