March 08, 2021 2m read

New Microsoft Exchange Vulnerability Disclosed

Dima Solomonov
Dima Solomonov
Microsoft Exchange Vulnerability Disclosed

Wondering where to begin your SASE journey?

We've got you covered!
Listen to post:
Getting your Trinity Audio player ready...

Several new CVEs targeting MS Exchange servers have been discovered and shared by Microsoft. Attacks using these CVEs include manipulation of domain admin accounts, deployment of a web shell and exfiltration of data.

Cato Networks security team has already developed and deployed the proper defenses for this new threat.

Earlier this week Microsoft disclosed a set of new 0-day CVEs (CVE-2021-26855, CVE-2021-26858, CVE-2021-26857, CVE-2021-27065) which were (and still are) used by the HALFIUM group to target Microsoft Exchange servers. These vulnerabilities were used by the attackers to create files and web shells using privileged users accounts which gave the attackers persistent access to the vulnerable servers as well as RCE (Remote Code Execution) capabilities and data exfiltration. According to available forensics and security investigations the affected entities were mainly US government entities and retailers.

As part of our research on new and emerging threats, Cato Networks researchers have found evidence of attackers (not necessarily the HALFIUM group) running a script to scan for vulnerable servers.

A code snippet from the scanning script
A code snippet from the scanning script

 

Additional Reading:
Microsoft official release: https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/

CNN: https://www.cnn.com/2021/03/03/tech/microsoft-exchange-server-hafnium-china-intl-hnk/index.html

Wondering where to begin your SASE journey?

We've got you covered!
Dima Solomonov

Dima Solomonov

Dima is a Principal Engineer at Cato Networks. Before joining Cato, he was an architect and platform team leader at SintecMedia. He is enthusiastic about emerging technologies, and his passions include taking cloud architecture projects under his wing, being involved in all parts of the workflow: from design to production code. In his free time, Dima likes to climb and dive. For pictures or collaboration, feel free to reach out.

Read More