Microsoft Exchange Zero-Day Vulnerabilities Exploited
ID: 5ae11ff8-5298-5870-b747-8ed3a66a0c9e
STIX ID: report--5ae11ff8-5298-5870-b747-8ed3a66a0c9e
Feed Name: Arctic Wolf Blog
Microsoft released an out-of-band patch for multiple critical Exchange vulnerabilities (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) that have been actively exploited by the China-linked HAFNIUM group since at least January 6, 2021; attackers chained SSRF, insecure deserialization, and post-auth arbitrary file-write flaws to achieve SYSTEM-level code execution and full mailbox access on on-prem Exchange 2013/2016/2019, and Arctic Wolf is updating detections and monitoring customer environments for related IOCs and TTPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
