Microsoft confirms two zero-days in Exchange Server 2013, 2016, and 2019 are being exploited in the wild; security firm GTSC suspects a Chinese threat actor
Microsoft has confirmed that two recently reported zero-day vulnerabilities in Microsoft Exchange Server 2013, 2016, and 2019 are being exploited in the wild.
The new confirmation puts the affected 2013, 2016, and 2019 deployments back into an active-incident posture, while GTSC's suspected Chinese attribution connects the event to the earlier pattern of state-linked Exchange targeting.
First-order effects
Organizations running the named Exchange Server versions face active exploitation risk now, requiring their security teams to prioritize containment and remediation over routine patch scheduling.
Microsoft must respond to an in-the-wild incident across three supported Exchange generations, while GTSC's attribution assessment concentrates attention on a suspected Chinese threat actor.
Second-order effects
Security teams are likely to give Exchange exposure priority over less immediately exploited vulnerabilities, particularly after the earlier multi-group exploitation of Exchange weaknesses showed how quickly campaigns can broaden.
Government and military Exchange operators draw added scrutiny because prior reporting identified backdoors on servers in those sectors, increasing the value of rapid incident review alongside remediation.
Third-order effects
Repeated exploitation of Exchange flaws by state-linked groups points to enterprise mail infrastructure as a durable high-value target, making legacy server exposure a continuing security-management issue rather than a one-off vulnerability event.
If this pattern persists, vendors and customers will be judged increasingly on how quickly they detect and contain active exploitation across installed server generations.
The trend: Enterprise messaging servers are becoming a recurring focus of state-linked intrusion campaigns, with active-exploitation alerts driving faster defensive response cycles.
🚨 There's reports emerging that a new zero day exists in Microsoft Exchange, and is being actively exploited in the wild 🚨 I can confirm significant numbers of Exchange servers have been backdoored - including a honeypot. Thread to track issue follows:
🚨 WARNING 🚨 Another day, another 0day exploited in the wild, this time for Exchange. https://gteltsc.vn/... If you have on-prem Exchange port 443 exposed, assume breach. There's no patch, so mitigate in place and search for IOC's. Then... start the migration project.
VULNERABILITY AFFECTING MICROSOFT EXCHANGE We are aware of open source reports of this vulnerability being exploited. We recommend organisations ensure they are running the latest Cumulative Update and Security Update and look into appropriate mitigations: https://gteltsc.vn/...
UPDATE: Microsoft has released a blog acknowledging the two zero-days and assigned these CVEs: CVE-2022-41040 and CVE-2022-41082. Mitigations are also discussed, read here: https://msrc-blog.microsoft.com/ ... https://twitter.com/...
Microsoft Exchange Online Customers do not need to take any action. On premises Microsoft Exchange customers, follow the blog to review and apply the URL Rewrite Instructions and block exposed Remote PowerShell ports.
“It should be noted that authenticated access to the vulnerable Exchange Server is necessary to successfully exploit either of the two vulnerabilities.” Well that's something at least. Also, read the text here about impacts on Exchange Online closely :) https://msrc-blog.microsof…
Importantly, MS has a mitigation that is effective “at breaking current attack chains” and that should not impact legit functionality. MS is going to patch out of band, and exploitation requires authentication. Still, strongly consider mitigating ASAP. https://msrc-blog.microsoft…
Security Alert: Two #zeroday vulnerabilities that were submitted to #Microsoft via @thezdi could allow attackers to perform remote code execution (RCE) on affected Microsoft Exchange servers. For more updates, keep watch here: https://research.trendmicro.com/ 3SKbGFT #0day @Trend…
Exchange server vuln summary Can be exploited if 1️⃣PowerShell port accessible (5985/5986) 2️⃣User creds required “Microsoft is aware of limited targeted attacks” “working on an accelerated timeline to release a fix” Mitigations & detection guidance 👇 https://msrc-blog.microsoft.…
Some explanations from MS concerning the Exchange 0d: https://msrc-blog.microsoft.com/ ... The attackers exploited 2 vulns and the first one needs to be authenticated.
Microsoft have a blog out. It's two new zero days indeed - however they need authentication. There's no technical info, but it looks like the Proxyshell issues weren't fully fixed. https://msrc-blog.microsoft.com/ ...
Microsoft have quietly deleted the guidance about blocking WinRM/PowerShell Remoting ports from their guidance. It was wrong. https://msrc-blog.microsoft.com/ ...
For the record this is the section Microsoft removed from the ProxyNotShell blog, and didn't document they had removed it. If you made firewall changes to prevent RCE, it didn't work. https://web.archive.org/... https://twitter.com/...
Microsoft has released mitigation advice for Exchange Server users regarding exploits on 2 new 0-day Exchange bugs. The attack requires authentication, but experts warn the China-based hacking group apparently involved is also phishing Exchange passwords https://krebsonsecurity.c…
Note regardless of the situation, if you have on-prem Exchange you should be preparing by getting it up-to-date and in a good healthy situation, right now. https://twitter.com/...
MS have issued two new CVEs overnight. The path for #ProxyNotShell is strikingly similar to ProxyShell, same as vuln classes. The detections from 2021 I wrote in the blog still work for ProxyNotShell. https://doublepulsar.com/...