{"id":25747,"date":"2022-11-10T18:49:52","date_gmt":"2022-11-10T18:49:52","guid":{"rendered":"https:\/\/www.esecurityplanet.com\/?p=25747"},"modified":"2022-11-11T00:09:17","modified_gmt":"2022-11-11T00:09:17","slug":"microsoft-proxynotshell-patch","status":"publish","type":"post","link":"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/","title":{"rendered":"ProxyNotShell Finally Gets Patched by Microsoft"},"content":{"rendered":"\n<p>Microsoft&#8217;s November 2022 <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2022-Nov\" target=\"_blank\" rel=\"noreferrer noopener\">Patch Tuesday<\/a> includes fixes for more than 60 vulnerabilities affecting almost 40 different products, features and roles \u2013 including patches for <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2022-41040\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2022-41040<\/a> and <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2022-41082\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2022-41082<\/a>, the <a href=\"https:\/\/www.esecurityplanet.com\/threats\/symantec-gtsc-warn-of-active-microsoft-exploits\/\" target=\"_blank\" rel=\"noreferrer noopener\">ProxyNotShell flaws<\/a> disclosed last month.<\/p>\n\n\n\n<p>&#8220;It took Microsoft more than two months to provide the patch, even though the company admitted that ProxyNotShell actively exploited the vulnerabilities in targeted attacks against at least 10 large organizations,&#8221; Mike Walters, vice president of vulnerability and threat research at Action1, said by email.<\/p>\n\n\n\n<p>&#8220;During this period, Microsoft proposed some <a href=\"https:\/\/www.esecurityplanet.com\/threats\/microsofts-fix-fails-to-patch-proxynotshell-rce-flaws\/\" target=\"_blank\" rel=\"noreferrer noopener\">mitigation measures<\/a>, which it revised in response to intense criticism,&#8221; Walters added. &#8220;However, even the revised measures have not been a panacea, so it is good news that an official patch is available now. Installing it promptly is highly advisable.&#8221;<\/p>\n\n\n\n<p>Regarding any previously applied mitigations for those flaws, the Microsoft Exchange Team <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/released-november-2022-exchange-server-security-updates\/ba-p\/3669045\" target=\"_blank\" rel=\"noreferrer noopener\">advised<\/a>, &#8220;Mitigations are not actual code fixes of specific vulnerabilities. Please install the November 2022 (or later) SU on your Exchange servers to address CVE-2022-41040 and CVE-2022-41082.&#8221;<\/p>\n\n\n\n<p>Also read: <a href=\"https:\/\/www.esecurityplanet.com\/applications\/patch-management-as-a-service\/\" target=\"_blank\" rel=\"noreferrer noopener\">Is the Answer to Vulnerabilities Patch Management as a Service?<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Other Threats Patched Too<\/h2>\n\n\n\n<p>Several other patches address flaws that are currently being exploited in the wild.<\/p>\n\n\n\n<p>One of those is <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2022-41128\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2022-41128<\/a>, a remote code execution flaw with a CVSS score of 8.8, impacting the JScript9 scripting language. &#8220;It has low complexity, uses the network vector, and requires no privilege to use, but it needs user interaction, such as using a phishing email to convince the victim to visit a malicious server share or website,&#8221; Walters said.<\/p>\n\n\n\n<p>In addition to installing the update, Walter suggested the flaw should serve as a reminder to <a href=\"https:\/\/www.esecurityplanet.com\/products\/cybersecurity-training\/\" target=\"_blank\" rel=\"noreferrer noopener\">train all users<\/a> on identifying and reporting <a href=\"https:\/\/www.esecurityplanet.com\/threats\/phishing-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing attacks<\/a>.<\/p>\n\n\n\n<p>Syxsense founder and CEO Ashley Leonard said by email that another flaw, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2022-41091\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2022-41091<\/a>, is notable due to the fact that the <a href=\"https:\/\/www.esecurityplanet.com\/threats\/ransomware-group-bypasses-windows-10-warnings\/\" target=\"_blank\" rel=\"noreferrer noopener\">steps to exploit it are available online<\/a>. &#8220;An attacker can craft a malicious file that would evade Mark of the Web (MOTW) defenses, resulting in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging,&#8221; Leonard said.<\/p>\n\n\n\n<p>Automox researcher Gina Geisel noted that <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2022-41125\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2022-41125<\/a>, a privilege escalation flaw in Windows CNG Key Isolation Service, is also being actively exploited. &#8220;With a long list of Windows 10 and 11 impacted (in addition to Win 8.0, 7.0, Server 2008, 2012, 2016, 2019, 2022, and 2022 Azure), this vulnerability exposes industry-leading versions of Windows and could have wide-ranging impacts,&#8221; she wrote in a <a href=\"https:\/\/www.automox.com\/blog\/patch-tuesday-november-2022\" target=\"_blank\" rel=\"noreferrer noopener\">blog post<\/a>.<\/p>\n\n\n\n<p>And Qualys director of vulnerability and threat research Bharat Jogi highlighted <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2022-41073\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2022-41073<\/a>, a Windows Print Spooler privilege escalation vulnerability that&#8217;s also being exploited in the wild. &#8220;Print Spooler is not new to zero days by any means, with a multitude of vulnerabilities having been identified over the years \u2013 one of which was used in the highly sophisticated nation-state <a href=\"https:\/\/www.esecurityplanet.com\/threats\/advanced-persistent-threat\/\" target=\"_blank\" rel=\"noreferrer noopener\">Stuxnet<\/a> attack,&#8221; he said.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Vulnerable Time of Year<\/h2>\n\n\n\n<p>While patching critical flaws like ProxyNotShell immediately is always important, Jogi noted one additional reason to take patching seriously now: the coming holidays.<\/p>\n\n\n\n<p>&#8220;As we approach the holiday season, security teams must be&nbsp;on high alert and increasingly&nbsp;vigilant,&nbsp;as attackers typically ramp up activity during this time&nbsp;(e.g., <a href=\"https:\/\/www.esecurityplanet.com\/threats\/log4j-vulnerability-ai-big-data-threat\/\" target=\"_blank\" rel=\"noreferrer noopener\">Log4j<\/a>, <a href=\"https:\/\/www.esecurityplanet.com\/threats\/solarwinds-attackers-targeting-resellers-service-providers\/\" target=\"_blank\" rel=\"noreferrer noopener\">SolarWinds<\/a> etc.),&#8221; Jogi said. &#8220;It is likely we will see bad actors attempting to take advantage of&nbsp;disclosed&nbsp;zero days&nbsp;and vulnerabilities released that organizations have left&nbsp;unpatched.&#8221;<\/p>\n\n\n\n<p>See the <a href=\"https:\/\/www.esecurityplanet.com\/products\/patch-management-software\/\">Top Patch Management Products<\/a><\/p>\n\n\n<div id=\"ta-campaign-widget-66d6f00651a2f-popup-wrapper\" class=\"ta-campaign-widget__popup-wrapper\">\n    \n<div\n    style=\"\n        --ta-campaign-plugin-primary: #3545ed;\n        --ta-campaign-plugin-button-text: #fff;\n        --ta-campaign-plugin-button-hover-background: #3231b4;\n        --ta-campaign-plugin-button-hover-text: #fff;\n        --ta-campaign-plugin-button-toggle-background: #3231b4;\n        --ta-campaign-plugin-button-toggle-text: #3231B4;\n    \"\n    data-ajax-url=\"https:\/\/www.esecurityplanet.com\/wp\/wp-admin\/admin-ajax.php\">\n    <div\n        id=\"ta-campaign-widget-66d6f00651a2f\"\n        class=\"ta-campaign-widget ta-campaign-widget--popup\"\n        data-campaign-fields='{\"properties\":{\"campaign_type\":\"popup\",\"campaign_category\":false,\"sailthru_list\":[\"cybersecurity-insider\"],\"popup_type\":\"exit_intent\",\"appearance\":{\"colors\":{\"primary_color\":\"#3545ed\",\"button\":{\"button_text_color\":\"#fff\",\"hover\":{\"button_hover_background_color\":\"#3231b4\",\"button_hover_text_color\":\"#fff\"},\"toggle\":{\"button_toggle_background_color\":\"#3231b4\",\"button_toggle_text_color\":\"#3231B4\"}}},\"custom_scss\":\"\"},\"behavior\":{\"opt_in_enabled\":true},\"language\":{\"tagline\":\"Get the Free Cybersecurity Newsletter\",\"subtagline\":\"\",\"content\":\"Strengthen your organization&#39;s IT security defenses by keeping up to date on the latest cybersecurity news, solutions, and best practices. Delivered every Monday, Tuesday and Thursday\",\"email_placeholder\":\"Work Email Address\",\"opt_in\":\"By signing up to receive our newsletter, you agree to our Terms of Use and Privacy Policy. You can unsubscribe at any time.\",\"subscribe_button\":\"Subscribe\"}},\"identifier\":\"66d6f00651a2f\",\"campaign_id\":26045,\"campaign_type\":\"popup\",\"popup_type\":\"exit_intent\",\"newsletters\":[\"cybersecurity-insider\"],\"behavior\":{\"opt_in_enabled\":true},\"appearance\":{\"colors\":{\"primary\":\"#3545ed\",\"button\":{\"text\":\"#fff\",\"hover\":{\"background\":\"#3231b4\",\"text\":\"#fff\"},\"toggle\":{\"background\":\"#3231b4\",\"text\":\"#3231B4\"}}},\"custom_css\":\"\"},\"language\":{\"tagline\":\"Get the Free Cybersecurity Newsletter\",\"subtagline\":\"\",\"content\":\"Strengthen your organization&#39;s IT security defenses by keeping up to date on the latest cybersecurity news, solutions, and best practices. Delivered every Monday, Tuesday and Thursday\",\"email_placeholder\":\"Work Email Address\",\"opt_in\":\"By signing up to receive our newsletter, you agree to our Terms of Use and Privacy Policy. You can unsubscribe at any time.\",\"subscribe_button\":\"Subscribe\"}}'>\n\n                <div class=\"ta-campaign-widget__exit\">\n            <svg class=\"w-8\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" viewBox=\"0 0 24 24\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" aria-hidden=\"true\">\n                <path stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M6 18L18 6M6 6l12 12\"><\/path>\n            <\/svg>\n        <\/div>\n        \n        <div class=\"ta-campaign-widget__wrapper\">\n            <div class=\"ta-campaign-widget__header mb-6\">\n                                <h3 class=\"ta-campaign-widget__tagline\">\n                    Get the Free Cybersecurity Newsletter                <\/h3>\n                \n                \n                                <p class=\"ta-campaign-widget__content mt-6\">\n                    Strengthen your organization's IT security defenses by keeping up to date on the latest cybersecurity news, solutions, and best practices. Delivered every Monday, Tuesday and Thursday                <\/p>\n                            <\/div>\n\n            <form class=\"ta-campaign-widget__form\">\n                <div class=\"ta-campaign-widget__input mb-4\"  data-field=\"email\">\n                    <label\n                        class=\"sr-only\"\n                        for=\"email-66d6f00651a2f\">\n                        Email Address\n                    <\/label>\n                    <input\n                        class=\"ta-campaign-widget__input__text\"\n                        placeholder=\"Work Email Address\"\n                        id=\"email-66d6f00651a2f\"\n                        name=\"email\"\n                        type=\"email\">\n                <\/div>\n\n                                <div class=\"ta-campaign-widget__checkbox mb-4\" data-field=\"opt_in\">\n                    <div class=\"flex items-start\">\n                        <input\n                            id=\"opt-in-66d6f00651a2f\"\n                            class=\"ta-campaign-widget__checkbox__input mr-2\"\n                            name=\"opt-in\"\n                            type=\"checkbox\"\/>\n                        <label\n                            class=\"ta-campaign-widget__checkbox__label\"\n                            for=\"opt-in-66d6f00651a2f\">\n                            By signing up to receive our newsletter, you agree to our Terms of Use and Privacy Policy. You can unsubscribe at any time.                        <\/label>\n                    <\/div>\n                <\/div>\n                \n                <button class=\"ta-campaign-widget__button\" type=\"submit\" >\n                    Subscribe                <\/button>\n            <\/form>\n        <\/div>\n    <\/div>\n<\/div>\n\n<style>\n<\/style><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft&#8217;s November 2022 Patch Tuesday includes fixes for more than 60 vulnerabilities affecting almost 40 different products, features and roles \u2013 including patches for CVE-2022-41040 and CVE-2022-41082, the ProxyNotShell flaws disclosed last month. &#8220;It took Microsoft more than two months to provide the patch, even though the company admitted that ProxyNotShell actively exploited the vulnerabilities [&hellip;]<\/p>\n","protected":false},"author":166,"featured_media":25751,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_gazelle_contributing_experts":"","footnotes":""},"categories":[15],"tags":[3790,1146,532,3414,730,5277],"b2b_audience":[33,35],"b2b_industry":[],"b2b_product":[382,31780,31782],"class_list":["post-25747","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threats","tag-cybersecurity","tag-malware","tag-microsoft","tag-network-security","tag-security","tag-web-security","b2b_audience-awareness-and-consideration","b2b_audience-implementation-and-support","b2b_product-application-security-vulnerability-management","b2b_product-patch-management","b2b_product-threat-intelligence"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>ProxyNotShell Finally Gets Patched by Microsoft | eSecurity Planet<\/title>\n<meta name=\"description\" content=\"Microsoft finally releases patches for the critical ProxyNotShell bug - and a lot of other important vulnerabilities too.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ProxyNotShell Finally Gets Patched by Microsoft | eSecurity Planet\" \/>\n<meta property=\"og:description\" content=\"Microsoft finally releases patches for the critical ProxyNotShell bug - and a lot of other important vulnerabilities too.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/\" \/>\n<meta property=\"og:site_name\" content=\"eSecurity Planet\" \/>\n<meta property=\"article:published_time\" content=\"2022-11-10T18:49:52+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-11-11T00:09:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/assets.esecurityplanet.com\/uploads\/2022\/11\/Nov2022SUPath.png\" \/>\n\t<meta property=\"og:image:width\" content=\"999\" \/>\n\t<meta property=\"og:image:height\" content=\"277\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Jeff Goldman\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@eSecurityPlanet\" \/>\n<meta name=\"twitter:site\" content=\"@eSecurityPlanet\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jeff Goldman\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/\"},\"author\":{\"name\":\"Jeff Goldman\",\"@id\":\"https:\/\/www.esecurityplanet.com\/#\/schema\/person\/814377f0182cc43200a4581fba4ec795\"},\"headline\":\"ProxyNotShell Finally Gets Patched by Microsoft\",\"datePublished\":\"2022-11-10T18:49:52+00:00\",\"dateModified\":\"2022-11-11T00:09:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/\"},\"wordCount\":571,\"publisher\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2022\/11\/Nov2022SUPath.png\",\"keywords\":[\"cybersecurity\",\"malware\",\"Microsoft\",\"network security\",\"security\",\"Web security\"],\"articleSection\":[\"Threats\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/\",\"url\":\"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/\",\"name\":\"ProxyNotShell Finally Gets Patched by Microsoft | eSecurity Planet\",\"isPartOf\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2022\/11\/Nov2022SUPath.png\",\"datePublished\":\"2022-11-10T18:49:52+00:00\",\"dateModified\":\"2022-11-11T00:09:17+00:00\",\"description\":\"Microsoft finally releases patches for the critical ProxyNotShell bug - and a lot of other important vulnerabilities too.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/#primaryimage\",\"url\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2022\/11\/Nov2022SUPath.png\",\"contentUrl\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2022\/11\/Nov2022SUPath.png\",\"width\":999,\"height\":277,\"caption\":\"ProxyNotShell patch\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.esecurityplanet.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ProxyNotShell Finally Gets Patched by Microsoft\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.esecurityplanet.com\/#website\",\"url\":\"https:\/\/www.esecurityplanet.com\/\",\"name\":\"eSecurity Planet\",\"description\":\"Industry-leading guidance and analysis for how to keep your business secure.\",\"publisher\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.esecurityplanet.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.esecurityplanet.com\/#organization\",\"name\":\"eSecurityPlanet\",\"url\":\"https:\/\/www.esecurityplanet.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.esecurityplanet.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2020\/10\/eSecurity_logo_MainLogo.png\",\"contentUrl\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2020\/10\/eSecurity_logo_MainLogo.png\",\"width\":1134,\"height\":375,\"caption\":\"eSecurityPlanet\"},\"image\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/eSecurityPlanet\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.esecurityplanet.com\/#\/schema\/person\/814377f0182cc43200a4581fba4ec795\",\"name\":\"Jeff Goldman\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.esecurityplanet.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/08\/jeff-goldman-150x150.jpg\",\"contentUrl\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/08\/jeff-goldman-150x150.jpg\",\"caption\":\"Jeff Goldman\"},\"description\":\"eSecurity Planet contributor Jeff Goldman has been a technology journalist for more than 20 years and an eSecurity Planet contributor since 2009. He's also written extensively about wireless and broadband infrastructure and semiconductor engineering. He started his career at MTV, but soon decided that technology writing was a more promising path.\",\"url\":\"https:\/\/www.esecurityplanet.com\/author\/jeff-goldman\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ProxyNotShell Finally Gets Patched by Microsoft | eSecurity Planet","description":"Microsoft finally releases patches for the critical ProxyNotShell bug - and a lot of other important vulnerabilities too.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/","og_locale":"en_US","og_type":"article","og_title":"ProxyNotShell Finally Gets Patched by Microsoft | eSecurity Planet","og_description":"Microsoft finally releases patches for the critical ProxyNotShell bug - and a lot of other important vulnerabilities too.","og_url":"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/","og_site_name":"eSecurity Planet","article_published_time":"2022-11-10T18:49:52+00:00","article_modified_time":"2022-11-11T00:09:17+00:00","og_image":[{"width":999,"height":277,"url":"https:\/\/assets.esecurityplanet.com\/uploads\/2022\/11\/Nov2022SUPath.png","type":"image\/png"}],"author":"Jeff Goldman","twitter_card":"summary_large_image","twitter_creator":"@eSecurityPlanet","twitter_site":"@eSecurityPlanet","twitter_misc":{"Written by":"Jeff Goldman","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/#article","isPartOf":{"@id":"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/"},"author":{"name":"Jeff Goldman","@id":"https:\/\/www.esecurityplanet.com\/#\/schema\/person\/814377f0182cc43200a4581fba4ec795"},"headline":"ProxyNotShell Finally Gets Patched by Microsoft","datePublished":"2022-11-10T18:49:52+00:00","dateModified":"2022-11-11T00:09:17+00:00","mainEntityOfPage":{"@id":"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/"},"wordCount":571,"publisher":{"@id":"https:\/\/www.esecurityplanet.com\/#organization"},"image":{"@id":"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/#primaryimage"},"thumbnailUrl":"https:\/\/assets.esecurityplanet.com\/uploads\/2022\/11\/Nov2022SUPath.png","keywords":["cybersecurity","malware","Microsoft","network security","security","Web security"],"articleSection":["Threats"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/","url":"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/","name":"ProxyNotShell Finally Gets Patched by Microsoft | eSecurity Planet","isPartOf":{"@id":"https:\/\/www.esecurityplanet.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/#primaryimage"},"image":{"@id":"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/#primaryimage"},"thumbnailUrl":"https:\/\/assets.esecurityplanet.com\/uploads\/2022\/11\/Nov2022SUPath.png","datePublished":"2022-11-10T18:49:52+00:00","dateModified":"2022-11-11T00:09:17+00:00","description":"Microsoft finally releases patches for the critical ProxyNotShell bug - and a lot of other important vulnerabilities too.","breadcrumb":{"@id":"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/#primaryimage","url":"https:\/\/assets.esecurityplanet.com\/uploads\/2022\/11\/Nov2022SUPath.png","contentUrl":"https:\/\/assets.esecurityplanet.com\/uploads\/2022\/11\/Nov2022SUPath.png","width":999,"height":277,"caption":"ProxyNotShell patch"},{"@type":"BreadcrumbList","@id":"https:\/\/www.esecurityplanet.com\/threats\/microsoft-proxynotshell-patch\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.esecurityplanet.com\/"},{"@type":"ListItem","position":2,"name":"ProxyNotShell Finally Gets Patched by Microsoft"}]},{"@type":"WebSite","@id":"https:\/\/www.esecurityplanet.com\/#website","url":"https:\/\/www.esecurityplanet.com\/","name":"eSecurity Planet","description":"Industry-leading guidance and analysis for how to keep your business secure.","publisher":{"@id":"https:\/\/www.esecurityplanet.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.esecurityplanet.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.esecurityplanet.com\/#organization","name":"eSecurityPlanet","url":"https:\/\/www.esecurityplanet.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.esecurityplanet.com\/#\/schema\/logo\/image\/","url":"https:\/\/assets.esecurityplanet.com\/uploads\/2020\/10\/eSecurity_logo_MainLogo.png","contentUrl":"https:\/\/assets.esecurityplanet.com\/uploads\/2020\/10\/eSecurity_logo_MainLogo.png","width":1134,"height":375,"caption":"eSecurityPlanet"},"image":{"@id":"https:\/\/www.esecurityplanet.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/eSecurityPlanet"]},{"@type":"Person","@id":"https:\/\/www.esecurityplanet.com\/#\/schema\/person\/814377f0182cc43200a4581fba4ec795","name":"Jeff Goldman","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.esecurityplanet.com\/#\/schema\/person\/image\/","url":"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/08\/jeff-goldman-150x150.jpg","contentUrl":"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/08\/jeff-goldman-150x150.jpg","caption":"Jeff Goldman"},"description":"eSecurity Planet contributor Jeff Goldman has been a technology journalist for more than 20 years and an eSecurity Planet contributor since 2009. He's also written extensively about wireless and broadband infrastructure and semiconductor engineering. He started his career at MTV, but soon decided that technology writing was a more promising path.","url":"https:\/\/www.esecurityplanet.com\/author\/jeff-goldman\/"}]}},"_links":{"self":[{"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/posts\/25747"}],"collection":[{"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/users\/166"}],"replies":[{"embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/comments?post=25747"}],"version-history":[{"count":0,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/posts\/25747\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/media\/25751"}],"wp:attachment":[{"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/media?parent=25747"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/categories?post=25747"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/tags?post=25747"},{"taxonomy":"b2b_audience","embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/b2b_audience?post=25747"},{"taxonomy":"b2b_industry","embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/b2b_industry?post=25747"},{"taxonomy":"b2b_product","embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/b2b_product?post=25747"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}