Microsoft Exchange Server Multiple Vulnerabilities
RISK: Extremely High Risk
TYPE: Servers - Internet App Servers
Multiple vulnerabilities were identified in Microsoft Exchange Server, a remote attacker could exploit some of these vulnerabilities to trigger remote code execution, security restriction bypass and data manipulation on the targeted system.
Note:
CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065 are being exploited in the wild. It is reported that multiple hacking groups are actively exploiting the vulnerabilities to deploy ransomware.
[Updated 8-Mar-2021] Add new link to the "Related Links" Section.
[Updated 16-Mar-2021] Add mitigation tool to the "Solution" Section.
[Updated 22-Mar-2021] Escalate to Extremely High risk. Add information about ransomware exploiting the vulnerabilities.
Impact
- Remote Code Execution
- Security Restriction Bypass
- Data Manipulation
System / Technologies affected
- Microsoft Exchange Server 2013
- Microsoft Exchange Server 2016
- Microsoft Exchange Server 2019
Solutions
Before installation of the software, please visit the vendor web-site for more details.
- Apply fixes issued by the vendor.
- Apply Microsoft Exchange On-Premises Mitigation Tool.
Vulnerability Identifier
Source
Related Link
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26412
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26854
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26855
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26857
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26858
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-27065
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-27078
- https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server
- https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers
- https://us-cert.cisa.gov/ncas/current-activity/2021/03/02/microsoft-releases-out-band-security-updates-exchange-server
Related Tags
Share with