Microsoft: Chinese APT Targeted Exchange Servers With Four Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-26855 | Unauthenticated SSRF/RCE in Microsoft Exchange Server (ProxyLogon) CVE-2021-26855 is a server-side request forgery flaw (CWE-918) in Microsoft Exchange Server that allows an unauthenticated remote attacker to send specially crafted HTTP requests and have the Exchange server process them as itself, disclosing sensitive session information. When chained with sibling Exchange flaws (the 'ProxyLogon' chain), it yields authentication bypass and arbitrary file write, escalating to full remote code execution with SYSTEM-level privileges on the on-premises Exchange server. Any organization running an affected on-premises Exchange server reachable over HTTP/HTTPS (typically outbound webmail) is exposed; Exchange Online was not affected. Exploitation is confirmed in the wild at large scale: the flaw was mass-exploited beginning in early 2021 (notably by the HAFNIUM group), is on the CISA KEV with documented ransomware use, and has a maximum EPSS score of 100% (100th percentile), despite no public PoC listing. Do: Apply the vendor's March 2021 Exchange security updates (or later cumulative updates) immediately, per the CISA required action; until patched, limit Exchange (ECP/OWA) exposure to the internet via firewall/VPN rules. Hunt for compromise: review IIS logs for unrecognized authenticated activity against FrontEnd HttpProxy endpoints, and check for malicious files or webshells under inetpub\wwwroot\aspnet_client, given the known ransomware use. | 9.1 group max | 100% | KEV ransomware PoC ×4 |
| masshundreds of thousands of on-premises deployments; tens of thousands of internet-exposed Exchange servers |
Full article399 words · extracted from therecord.media · click to collapse
Technology giant Microsoft released emergency security updates today for its Exchange email server to patch four zero-day vulnerabilities that were exploited by a Chinese state-sponsored hacking group. Named Hafnium, Microsoft said the group has a history of targeting internet-facing servers as an entry point into its targets' internal networks. In past attacks, the group has primarily targeted entities in the United States, such as infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. Its most recent wave of attacks took place this year and have involved the use of four previously unknown Exchange bugs. In reports published today by both Microsoft and security firm Volexity, the companies said that Hafnium operators used the four Exchange zero-days as part of a multi-part attack chain to bypass authentication procedures, gain admin privileges, and then install an ASPX web shell on the compromised servers. Once attackers had a foothold inside an organization's Exchange server, they proceeded to export the content of email inboxes and address books and upload the data to a remote server. It's these suspicious uploads that Volexity said it detected on the Exchange servers of two of its customers. A subsequent investigation discovered ongoing attacks, and the security firm said it reported its findings to Microsoft. Volexity also said it tracked down attacks going as far back as January 2021. Microsoft also said it received a second report about the attacks from Danish security firm Dubex. Earlier today, Microsoft has released patches for the four zero-days exploited in the attacks (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065), but also for three other Exchange bugs (CVE-2021-27078, CVE-2021-26854, and CVE-2021-26412) it discovered during the subsequent investigation. The OS maker said that only Exchange email servers installed on customer premises were vulnerable and that Exchange Online systems were not vulnerable. While neither Microsoft nor Volexity disclosed the targets of these recent attacks, in a blog post today, Tom Burt, Microsoft Corporate Vice-President of Consumer Trust and Safety, said they've "briefed appropriate U.S. government agencies on this activity."Zero-days were part of an attack chain
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/chinese-apt-targeted-exchange-servers-with-four-zero-days-microsoft-says