Microsoft One-Click Tool Mitigates Exchange Server Attacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-26855 | Unauthenticated SSRF/RCE in Microsoft Exchange Server (ProxyLogon) CVE-2021-26855 is a server-side request forgery flaw (CWE-918) in Microsoft Exchange Server that allows an unauthenticated remote attacker to send specially crafted HTTP requests and have the Exchange server process them as itself, disclosing sensitive session information. When chained with sibling Exchange flaws (the 'ProxyLogon' chain), it yields authentication bypass and arbitrary file write, escalating to full remote code execution with SYSTEM-level privileges on the on-premises Exchange server. Any organization running an affected on-premises Exchange server reachable over HTTP/HTTPS (typically outbound webmail) is exposed; Exchange Online was not affected. Exploitation is confirmed in the wild at large scale: the flaw was mass-exploited beginning in early 2021 (notably by the HAFNIUM group), is on the CISA KEV with documented ransomware use, and has a maximum EPSS score of 100% (100th percentile), despite no public PoC listing. Do: Apply the vendor's March 2021 Exchange security updates (or later cumulative updates) immediately, per the CISA required action; until patched, limit Exchange (ECP/OWA) exposure to the internet via firewall/VPN rules. Hunt for compromise: review IIS logs for unrecognized authenticated activity against FrontEnd HttpProxy endpoints, and check for malicious files or webshells under inetpub\wwwroot\aspnet_client, given the known ransomware use. | 9.1 | 100% | KEV ransomware PoC ×4 |
| masshundreds of thousands of on-premises deployments; tens of thousands of internet-exposed Exchange servers |
Full article318 words · extracted from infosecurity-magazine.com · click to collapse
Microsoft has released a “one-click” tool to help organizations with limited resources to temporarily mitigate the threat posed by recent global attacks on Exchange servers.
The “Microsoft Exchange On-Premises Mitigation Tool” has been designed for customers without dedicated IT or cybersecurity resources to help them patch the four zero-days being exploited in the wild, now know as “ProxyLogon” attacks.
“By downloading and running this tool, which includes the latest Microsoft Safety Scanner, customers will automatically mitigate CVE-2021-26855 on any Exchange server on which it is deployed,” Microsoft said.
“This tool is not a replacement for the Exchange security update but is the fastest and easiest way to mitigate the highest risks to internet-connected, on-premises Exchange Servers prior to patching.”
Once it has been run, the tool will mitigate attacks exploiting the above CVE, using a “URL rewrite configuration.” It will also run the Microsoft Safety Scanner and attempt to reverse any changes made by identified threats.
However, the Redmond giant was at pains to point out the tool shouldn’t be used as a replacement for patching, as it only works against attacks seen so far, and “is not guaranteed to mitigate all possible future attack techniques.”
Check Point Research claimed yesterday that it had seen a sixfold increase in exploit attempts targeting the zero-days in Exchange Server Microsoft patched out-of-band at the start of the month.
Although initially Microsoft attributed attacks to a Chinese state-backed actor, dubbed Hafnium, researchers have since claimed that multiple APT groups have been attempting to exploit the same vulnerabilities for remote control, data theft, ransomware and more.
Microsoft warned last Friday that it had detected a new ransomware variant, DearCry, being used in attacks.
The firm has released new updates to cover end-of-life Exchange Server products, and cumulative updates which it said cover 95% of all versions exposed on the internet. As of Friday, around 80,000 servers were still unpatched globally.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-oneclick-tool-mitigates/