On Microsoft Exchange Server, security researchers have discovered a new exploit that enables attackers to remotely execute code over Outlook Web Access (OWA).
According to Crowdstrike, the new exploit approach overcomes the URL or link rewrite mitigations for the ProxyNotShell problem that Microsoft released and which affects on-premises Exchange servers by using two vulnerabilities.
The exploit technique was known as OWASSRF, or Outlook Web Access Server-Side Request Forgery, by the security provider.
An example of this kind of vulnerability is a server-side request forgery (SSRF).
The Remote PowerShell service is the backend service that ProxyNotShell is targeting.
Dray Agha, a security researcher at Huntresslabs, tweeted a proof-of-concept link that contained the new exploit’s disclosed source code.
Agha had downloaded them all after discovering the attackers’ toolkit in an open source.
Crowdstrike was able to duplicate the log file entries in recent attacks by employing a Python script that Agha posted.
A few days later, Rackspace acknowledged that a ransomware attack by unidentified criminals was to blame for the downtime, which required the company’s support staff to engage in time-consuming data recovery procedures for clients.
According to Rackspace, Crowdstrike was engaged to help with the ransomware attack investigation.
Because URL rewrite mitigations for ProxyNotShell are ineffective, according to Crowdstrike, Exchange administrators should implement Microsoft’s November fixes to stop exploitation.
Administrators who are unable to fix their Exchange servers right away should stop OWA as soon as they can and, if at all possible, adhere to Microsoft’s advice to turn off remote PowerShell for non-administrative users.

