Microsoft Exchange bugs top list of exploited vulnerabilities affecting financial sector
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2015-1635 | Unauthenticated Remote Code Execution in Microsoft HTTP.sys (MS15-034) CVE-2015-1635 is a remote code execution flaw in HTTP.sys, the kernel-mode HTTP protocol stack component of Microsoft Windows that handles HTTP(S) traffic for IIS and other web-facing Windows roles. A remote, unauthenticated attacker can trigger it by sending specially crafted HTTP requests to a system listening via HTTP.sys, most commonly an internet-facing IIS web server. Successful exploitation yields arbitrary code execution with kernel/system-level privileges on the target server, giving the attacker full control of the host. Any Windows deployment where HTTP.sys is reachable is affected - typically IIS web servers and web-facing roles such as Exchange or WSUS - although the source data does not specify exact version ranges. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-10) with a ~100% EPSS probability of exploitation within 30 days, indicating active exploitation; public proof-of-concept code is not noted in the data and ransomware use is unknown. Do: Apply Microsoft updates per vendor instructions (this CVE is addressed by the April 2015 MS15-034 bulletin) on every Windows system where HTTP.sys is reachable, prioritizing internet-facing IIS, Exchange, and WSUS hosts. Inventory your environment for systems running web-facing Windows roles and, if patching must be delayed, restrict inbound HTTP/80 and HTTPS/443 from untrusted sources or filter malformed HTTP requests at a front-end proxy/WAF. As a CISA KEV entry, this is a required patch for federal agencies; treat it as urgent everywhere else. | — | 100% | KEV |
| masshundreds of thousands of internet-exposed Windows/IIS servers | |
| CVE-2021-26855 | Unauthenticated SSRF/RCE in Microsoft Exchange Server (ProxyLogon) CVE-2021-26855 is a server-side request forgery flaw (CWE-918) in Microsoft Exchange Server that allows an unauthenticated remote attacker to send specially crafted HTTP requests and have the Exchange server process them as itself, disclosing sensitive session information. When chained with sibling Exchange flaws (the 'ProxyLogon' chain), it yields authentication bypass and arbitrary file write, escalating to full remote code execution with SYSTEM-level privileges on the on-premises Exchange server. Any organization running an affected on-premises Exchange server reachable over HTTP/HTTPS (typically outbound webmail) is exposed; Exchange Online was not affected. Exploitation is confirmed in the wild at large scale: the flaw was mass-exploited beginning in early 2021 (notably by the HAFNIUM group), is on the CISA KEV with documented ransomware use, and has a maximum EPSS score of 100% (100th percentile), despite no public PoC listing. Do: Apply the vendor's March 2021 Exchange security updates (or later cumulative updates) immediately, per the CISA required action; until patched, limit Exchange (ECP/OWA) exposure to the internet via firewall/VPN rules. Hunt for compromise: review IIS logs for unrecognized authenticated activity against FrontEnd HttpProxy endpoints, and check for malicious files or webshells under inetpub\wwwroot\aspnet_client, given the known ransomware use. | 9.1 group max | 100% | KEV ransomware PoC ×4 |
| masshundreds of thousands of on-premises deployments; tens of thousands of internet-exposed Exchange servers | |
| CVE-2021-34523 +1 in the same advisory: …31206 | Privilege Escalation in Microsoft Exchange Server (ProxyShell) On-premises Microsoft Exchange Server contains an elevation-of-privilege flaw (CWE-287, improper authentication) in which Exchange performs an incorrect lookup of security descriptors for requests proxied to the Exchange PowerShell API. The flaw is reached through the Autodiscover endpoint and was published as the middle step of the 'ProxyShell' attack chain, where an unauthenticated attacker chains it with an SSRF bug (CVE-2021-34473) and a post-authentication RCE (CVE-2021-33768) to move from no access to running arbitrary code on the server. Successful exploitation lets an attacker impersonate a privileged Exchange account, gaining elevated privileges in the Exchange organization and, when chained, arbitrary code execution on the Exchange host. Any on-premises Exchange deployment is affected (Microsoft's advisory covers Exchange Server 2013, 2016, and 2019), with the greatest risk on servers whose Autodiscover/OWA endpoints are reachable from the internet. Exploitation is confirmed in the wild — the flaw is on CISA's KEV catalog (added 2021-11-03) with known ransomware use and an EPSS probability of 100% — even though no public proof-of-concept is known. Do: Apply Microsoft's July 2021 Exchange Server security updates for Exchange 2013, 2016, and 2019 as CISA's required action directs, prioritizing internet-facing servers given known ransomware use. Reduce exposure of Autodiscover/OWA endpoints (restrict to VPN or trusted networks where possible) and review IIS logs for suspicious requests to autodiscover/PowerShell endpoints as evidence of prior ProxyShell exploitation. | 9.0 group max | 100% | KEV ransomware PoC |
| mass≈300,000+ internet-exposed on-premises Exchange servers (order of hundreds of thousands in public internet scans around disclosure) | |
| CVE-2021-31207 | Security feature bypass in Microsoft Exchange Server (ProxyShell) enables webshell RCE CVE-2021-31207 is a security feature bypass in Microsoft Exchange Server, classified as an unrestricted file-write issue (CWE-434) that lets an attacker bypass intended restrictions and write files of their choosing to the server. It is the final bug in the ProxyShell chain: chained with the autodiscover SSRF and PowerShell backend elevation flaws, it allows an unauthenticated attacker to reach the Exchange PowerShell API, write arbitrary files such as an ASPX webshell, and execute code with SYSTEM privileges. A successful attacker gains full control of the on-premises Exchange server, including mailbox access, stolen credentials, and a foothold for lateral movement; the bug has been used to deploy ransomware and keyloggers. On-premises deployments of Microsoft Exchange Server (2013, 2016, and 2019 per vendor advisories) are affected, while Exchange Online/cloud mailboxes are not. Exploitation is essentially certain and ongoing: the flaw is in CISA's KEV (added 2021-11-03) with known ransomware use, public ProxyShell PoC/exploit code is available, and EPSS puts the 30-day exploitation probability at 99.8%. Do: Apply Microsoft's July 2021 security updates for Exchange Server 2013, 2016, and 2019 (or any later security/cumulative update) per vendor instructions, and restrict untrusted access to Exchange's autodiscover and PowerShell endpoints. Hunt for ASPX webshells under the Exchange FrontEnd directories and review IIS logs for autodiscover.json requests chaining PowerShell, since many servers were compromised before patching. Given known ransomware use and KEV listing, treat any server that was unpatched or internet-exposed during the exploitation window as potentially compromised. | 6.6 | 100% | KEV ransomware PoC |
| massHundreds of thousands of on-premises Exchange servers (public scans around the July 2021 ProxyShell disclosure showed roughly 400,000-600,000 internet-exposed… |
Full article428 words · extracted from therecord.media · click to collapse
Two bugs affecting Microsoft products topped a survey of exploited vulnerabilities being used to target the U.S. financial services sector, according to new research. Researchers at the cybersecurity company LookingGlass examined public internet-facing assets from over 7 million IP addresses belonging to the sector in November 2022 – finding that a seven-year-old Remote Code Execution vulnerability affecting Microsoft Windows topped the list. "It was interesting to see that our research detected CVE-2015-1635, a Remote Code Execution vulnerability affecting Microsoft Windows, over 900 times in the finance sector, but this vulnerability is seven years old,” said LookingGlass CEO and former CISA Assistant Director Bryan Ware. “This goes to show that when hackers find a successful attack method, they continue to exploit it for years to come, particularly in highly advantageous industries like the financial sector." The next most common exploited vulnerability was CVE-2021-31206 affecting Microsoft Exchange Servers – one of the most popular bugs among cybercriminals and state-backed actors. CISA and several other cybersecurity agencies around the world warned in September that Iranian military groups were exploiting the bug widely. Several other Microsoft Exchange vulnerabilities made LookingGlass’ list, including CVE-2021-34523, CVE-2021-31207 and CVE-2021-34473 – known collectively as “ProxyShell.” They found the bugs exposed “almost 60 times in the sector” in November. The report notes that the notorious Chinese government hacking group called HAFNIUM was exploiting CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 – other vulnerabilities affecting Microsoft Exchange. “Across the U.S. financial sector, more than half of the vulnerabilities our platform detected reside in the insurance subsector, roughly a quarter fell under credit intermediaries, and about one in three of all vulnerabilities were carried over from third party services providers.” The report notes that the insurance subsector is a primary target for criminal activity because of how much personal information and financial data it holds. The U.S. Department of Treasury said in November that U.S. financial institutions absorbed nearly $1.2 billion in costs associated with ransomware attacks alone in 2021 – a nearly 200% increase over the previous year. There were 1,489 reported incidents, compared to 487 in 2020, with researchers reporting that “ransomware continues to pose a significant threat to U.S. critical infrastructure sectors, businesses, and the public.”
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/microsoft-exchange-bugs-top-list-of-exploited-vulnerabilities-affecting-financial-sector