• News/
  • https://www.theregister.com/2025/01/23/proxylogon_flaw_salt_typhoons_open/

ProxyLogon, one of Salt Typhoon's favorites, still wide open

The Register
·
Jessica Lyons
·
Published Jan 23, 2025
·
Updated

One of the critical security flaws exploited by China's Salt Typhoon to breach US telecom and government networks has had a patch available for nearly four years - yet despite repeated warnings from law enforcement and private-sector security firms, nearly all public-facing Microsoft Exchange Server instances with this vulnerability remain unpatched. According to cyber-risk management firm Tenable, 91 percent of the nearly 30,000 openly reachable instances of Exchange vulnerable to CVE-2021-26855, aka ProxyLogon, have not been updated to close the hole. Microsoft disclosed this vulnerability in March 2021, and warned it was being exploited with a chain of other bugs by Chinese government snoops to achieve remote code execution on targets' Exchange Servers. Later that year, the Five Eyes nations called ProxyLogon one of the top exploited vulnerabilities of 2021. For comparison: Tenable's team also analyzed over 20,000 devices suffering two Ivanti vulnerabilities (CVE-2023-46805 and CVE-2024-21887) also abused by Salt Typhoon and found that more than 92 percent of these devices were fully remediated. "Salt Typhoon is known for maintaining a stealthy presence on victim networks and remaining undetected for a significant time period," Scott Caveza, Tenable staff research engineer, said in a Thursday report. The snoops maintain persistence via custom malware including GhostSpider, SnappyBee, and the Masol remote access trojan, he added. This echoes an earlier report by Trend Micro...

Read full article

Affected Software

2 affected components
Microsoft Exchange Server
Microsoft Exchange Server
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the continued exploitation of the ProxyLogon vulnerability by China's Salt Typhoon, despite a patch being available for almost four years.

2

What security implications are discussed in the article?

The article highlights that the ProxyLogon flaw remains a significant threat, enabling attackers to breach U.S. telecom and government networks.

3

What products or software are affected by the ProxyLogon vulnerability?

The affected software is primarily Microsoft Exchange Server.

4

What actions have been taken regarding the ProxyLogon vulnerability?

A patch for the ProxyLogon vulnerability has been available for nearly four years, but many organizations have not implemented it.

5

Who is behind the attacks exploiting the ProxyLogon flaw?

The attacks exploiting the ProxyLogon flaw are attributed to a Chinese hacking group known as Salt Typhoon.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203