30 entries found.
Displaying page 1
of 2.
Backdoor:ASP/Webshell.Y
Updated on Aug 02, 2022
Microsoft Defender Antivirus detects and removes this threat.
This backdoor is associated with attacks that exploit vulnerabilities affecting Microsoft Exchange Server 2013, Exchange Server 2016, and Exchange Server 2019. The first one, identified as CVE-2022-41040, is a server-side request forgery (SSRF) vulnerability, while the second one, identified as CVE-2022-41082, allows remote code execution (RCE) when Exchange PowerShell is accessible to the attacker.
This threat is leveraged by attackers to maintain access and persistence on a target device.
For more information and guidance from Microsoft about this threat, read the following blogs:
Alert level:
severe