logo

Microsoft Exchange Servers Still Vulnerable to ProxyShell Exploit | Huntress

ID: 05e831b5-fd27-526e-9640-0b827f90f8ff

STIX ID: report--05e831b5-fd27-526e-9640-0b827f90f8ff

Feed Name: Huntress Blog

Threat Score
85/100

Date Published: 2024-06-24

Date Updated: 2026-04-28

...
...

Huntress warns of active in-the-wild exploitation of Microsoft Exchange ProxyShell vulnerabilities where attackers implant hidden webshells (including via modified applicationHost.config virtual directories), observed across many servers; the report lists webshell file paths, filesystem locations (ProgramData, C:\Users\All Users, Exchange paths), sample IPs and user-agents, multiple webshell types/TTPs, and recommends urgent patching, removal of webshells, IIS restart, and firewall blocks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.