logo

Detection and response for the actively exploited ProxyShell vulnerabilities

ID: 81a865d3-d6a3-52cc-9a35-62d866288d4e

STIX ID: report--81a865d3-d6a3-52cc-9a35-62d866288d4e

Feed Name: Elastic Security Labs

Threat Score
80/100

Date Published: 2022-06-02

Date Updated: 2026-04-27

...
...

On August 21, 2021 CISA warned of active exploitation of ProxyShell Exchange vulnerabilities (CVE-2021-31207, CVE-2021-34473, CVE-2021-34523) that attackers chain to compromise unpatched Microsoft Exchange servers; security vendors and researchers observed post-exploitation activity including ransomware deployment, and Elastic Security published IoCs and telemetry details for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.