Microsoft Exchange 0-day Vulnerability Analysis
ID: 10e6b226-3a24-542e-b458-bc6fd2c70df6
STIX ID: report--10e6b226-3a24-542e-b458-bc6fd2c70df6
Feed Name: Censys Blog
In March 2021 Microsoft released patches for critical Microsoft Exchange vulnerabilities (including CVE-2021-26855 and CVE-2021-27065) that were actively exploited in the wild since early January; attackers used SSRF to access mailboxes, chained to RCE to deploy web shells, exfiltrate email data, move laterally, and potentially install further malware or ransomware. Censys observed over 251,000 Exchange servers online with more than half running affected CU versions across many countries and industries; the report urges immediate use of Microsoft detection scripts and application of security updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
