Microsoft confirms two zero-days in Exchange Server 2013, 2016, and 2019 are being exploited in the wild; security firm GTSC suspects a Chinese threat actor
Microsoft has confirmed that two recently reported zero-day vulnerabilities in Microsoft Exchange Server 2013, 2016, and 2019 are being exploited in the wild.
The new confirmation places the affected Exchange generations back in an active-exploitation cycle. GTSC's attribution is a suspicion, but the immediate operational fact is Microsoft's confirmation that attackers are using the two flaws in the wild.
First-order effects
Organizations running the affected Exchange Server versions must treat exposed servers as potential incident-response cases, rather than merely a routine vulnerability-management task.
Microsoft faces renewed pressure from Exchange customers for mitigation guidance as active exploitation broadens the urgency beyond GTSC's initial reporting.
Second-order effects
Security teams will prioritize Exchange monitoring and containment ahead of lower-risk patch work, reflecting the damage potential established by the earlier actively exploited Exchange zero-days.
The suspected Chinese connection will focus defenders' attention on targeted government and military environments, which related coverage shows have previously been backdoored through Exchange.
Third-order effects
Repeated active exploitation makes self-hosted messaging infrastructure a durable concentration point for state-linked intrusion campaigns, increasing the premium on rapid detection and response around widely deployed enterprise software.
If exploitation of Exchange continues to recur, enterprise buyers and Microsoft will face stronger incentives to reduce the exposure window between flaw disclosure and defensive action.
The trend: Exchange is becoming a recurring focal point in the broader pattern of state-linked actors weaponizing newly disclosed enterprise-software flaws before defenders can respond.
🚨 There's reports emerging that a new zero day exists in Microsoft Exchange, and is being actively exploited in the wild 🚨 I can confirm significant numbers of Exchange servers have been backdoored - including a honeypot. Thread to track issue follows:
🚨 WARNING 🚨 Another day, another 0day exploited in the wild, this time for Exchange. https://gteltsc.vn/... If you have on-prem Exchange port 443 exposed, assume breach. There's no patch, so mitigate in place and search for IOC's. Then... start the migration project.
VULNERABILITY AFFECTING MICROSOFT EXCHANGE We are aware of open source reports of this vulnerability being exploited. We recommend organisations ensure they are running the latest Cumulative Update and Security Update and look into appropriate mitigations: https://gteltsc.vn/...
UPDATE: Microsoft has released a blog acknowledging the two zero-days and assigned these CVEs: CVE-2022-41040 and CVE-2022-41082. Mitigations are also discussed, read here: https://msrc-blog.microsoft.com/ ... https://twitter.com/...
Microsoft Exchange Online Customers do not need to take any action. On premises Microsoft Exchange customers, follow the blog to review and apply the URL Rewrite Instructions and block exposed Remote PowerShell ports.
“It should be noted that authenticated access to the vulnerable Exchange Server is necessary to successfully exploit either of the two vulnerabilities.” Well that's something at least. Also, read the text here about impacts on Exchange Online closely :) https://msrc-blog.microsof…
Importantly, MS has a mitigation that is effective “at breaking current attack chains” and that should not impact legit functionality. MS is going to patch out of band, and exploitation requires authentication. Still, strongly consider mitigating ASAP. https://msrc-blog.microsoft…
Security Alert: Two #zeroday vulnerabilities that were submitted to #Microsoft via @thezdi could allow attackers to perform remote code execution (RCE) on affected Microsoft Exchange servers. For more updates, keep watch here: https://research.trendmicro.com/ 3SKbGFT #0day @Trend…
Exchange server vuln summary Can be exploited if 1️⃣PowerShell port accessible (5985/5986) 2️⃣User creds required “Microsoft is aware of limited targeted attacks” “working on an accelerated timeline to release a fix” Mitigations & detection guidance 👇 https://msrc-blog.microsoft.…
Some explanations from MS concerning the Exchange 0d: https://msrc-blog.microsoft.com/ ... The attackers exploited 2 vulns and the first one needs to be authenticated.
Microsoft have a blog out. It's two new zero days indeed - however they need authentication. There's no technical info, but it looks like the Proxyshell issues weren't fully fixed. https://msrc-blog.microsoft.com/ ...