The history of ProxyNotShell, the Microsoft vulnerability
ID: b5a1b0b7-419f-5e10-be94-c9cfe72ab702
STIX ID: report--b5a1b0b7-419f-5e10-be94-c9cfe72ab702
Feed Name: ThreatLocker Blog
Threat Score
ProxyNotShell is an evolved exploit chain against Microsoft Exchange (notably CVE-2022-41040 and CVE-2022-41082) that followed the earlier ProxyShell flaws; it enables SSRF leading to remote code execution, was observed in limited targeted attacks, has had mitigations bypassed (OWASSRF), left many internet-facing Exchange instances vulnerable, and highlights the need for immediate patching and layered defensive measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
