Concerns as Ransomware and Exchange Server Attacks Surge
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-27065 | ProxyLogon chain RCE in Microsoft Exchange Server (CVE-2021-27065) CVE-2021-27065 is a remote code execution vulnerability in on-premises Microsoft Exchange Server, best known as the file-write component of the ProxyLogon exploit chain disclosed in March 2021. The flaw lets an attacker write arbitrary files, such as web shells, to the Exchange web server, and when chained with the pre-authentication SSRF bug in the same ProxyLogon chain it yields fully unauthenticated code execution on the server. Successful exploitation gives attackers the ability to run commands as the Exchange server, access organizational email and data, establish persistence, and — as CISA notes — it has been used as a foothold for ransomware deployment. Any organization running an affected on-premises Exchange Server is exposed, particularly when Outlook Web Access or other Exchange endpoints are internet-reachable; this is a server-product flaw, not an Exchange Online/cloud-mailbox issue. Exploitation is confirmed and widespread: it is in the wild with known ransomware use, CISA added it to the KEV on 2021-11-03, and EPSS assigns a ~99.9% probability of exploitation within 30 days. Do: Apply Microsoft's March 2021 (or later) Exchange Server security updates immediately, consistent with CISA's required action to apply vendor updates. Hunt for ProxyLogon indicators — web shells under the Exchange FrontEnd HttpProxy folders (e.g., in owa/auth), unexpected files in the OAB virtual directory, and ransomware artifacts — using Microsoft's Safety Scanner or the Test-ProxyLogon tooling, and treat any hit as a full intrusion (scope persistence and rotate exposed credentials). If patching must be deferred, restrict or remove internet exposure of OWA/ECP and apply interim mitigations while monitoring for ransomware deployment. | 7.8 | 100% | KEV ransomware PoC ×2 |
| mass≈300,000–600,000 internet-exposed on-prem Exchange servers (order of magnitude: hundreds of thousands) |
Full article437 words · extracted from infosecurity-magazine.com · click to collapse
There are growing concerns that more unpatched Microsoft Exchange servers could be compromised in ransomware attacks after Check Point revealed major recent surges in ProxyLogon attacks and ransomware.
The security vendor claimed in new figures released today that it has detected a 57% increase in ransomware attacks over the past six months, with the number of affected organizations growing by 9% each month so far in 2021.
Human-operated variants such as Maze and Ryuk have been particularly prevalent over the period, with the US (12%), Israel (8%) and India (7%) the most affected countries.
Amazingly, WannaCry is trending again, four years after it caused global panic. Still using EternalBlue to propagate, the worm affected 53% more organizations in March than the start of the year.
At the same time as the continued surge in ransomware, Check Point has seen the number of attacks exploiting the ProxyLogon vulnerability to attack Exchange servers triple over the past week alone.
The most affected sectors are government/military, manufacturing and banking/finance, with the nearly half (49%) of all exploit attempts in the US, followed by the UK (5%), the Netherlands (4%) and Germany (4%).
Microsoft was the first to warn users that vulnerable Exchange endpoints could be hijacked by attackers to deploy ransomware. The DearCry variant was spotted doing so in the wild.
A few days later Sophos detected Black Kingdom ransomware being deployed in a similar way.
“The threat actor exploited the on-premises versions of Microsoft Exchange Server, abusing the remote code execution (RCE) vulnerability also known as ProxyLogon (CVE-2021-27065),” it said. “After successfully breaching the Exchange server, the adversary delivered a webshell. This webshell offers remote access to the server and allows the execution of arbitrary commands.”
The acting director of the Cybersecurity and Infrastructure Security Agency (CISA), Brandon Wales, has also urged Exchange server administrators to patch now or risk the same fate.
Check Point stopped short of linking the two trends, but joined the chorus of voices calling for urgent action to patch the remaining Exchange servers vulnerable to ProxyLogon.
“Although we have not concluded that the two trends are directly related just yet, there is reason for concern. We do believe the Microsoft Exchange vulnerabilities opened up another door into organizations. And so, Check Point Research is also raising the alarm bells, just like CISA has,” said threat intelligence manager, Lotem Finkelsteen.
“We’re urging organizations to act now, before ransomware gangs make Exchange exploits popular. In cybercrime, we rarely see businesses that demonstrate constant growth, or rapid adjustments to changing factors, as well as quick adoptions of new technologies. Ransomware is one of those rare businesses.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/concerns-ransomware-exchange/