Technology

BSI renews warning: Thousands of Exchange servers vulnerable

The Federal Office for Information Security (BSI) is again warning of security gaps in Microsoft Exchange Servers. Despite previous warnings, thousands of servers remain unpatched and vulnerable to cyberattacks. What is behind this ongoing problem?

Alarming downtime on Exchange servers

The Federal Office for Information Security (BSI) is sounding the alarm again: Thousands of Microsoft Exchange servers in Germany continue to have critical security gaps (via Günter Born). This worrying situation exists despite repeated warnings and the availability of security updates. The CERT-Bund, the BSI’s computer emergency unit, has published current figures that underline the urgency of the situation.

According to CERT-Bund, around 12,000 Microsoft Exchange Servers 2016 and 2019 can be accessed via the Internet with open Outlook Web Access (OWA), but do not have the latest security levels. This corresponds to around 28 percent of all Exchange servers of these versions in Germany. What is particularly alarming is that for around 6,500 systems, or 15 percent, the last security patch was installed over a year ago.

Critical security vulnerability

Two particularly critical vulnerabilities are the focus of the BSI warning. The vulnerability, known as CVE-2024-26198, allows an unauthenticated attacker to execute remote code. Microsoft has given this vulnerability a high risk score of 8.8. A patch to fix this was already released in March 2024.

Another serious vulnerability, CVE-2023-36439, allows authenticated attackers to gain extensive system privileges. This vulnerability was closed by Microsoft in November 2023. The fact that many servers are still vulnerable to these older vulnerabilities clearly shows how careless many organizations are with their IT systems.

Reasons for lack of patch discipline

The question that arises: Why are these critical updates not installed even though they are available for free? Experts suspect various reasons:

  • Lack of resources: Many IT departments are understaffed and do not have the capacity for regular maintenance.
  • Complexity: Updates can cause compatibility issues in complex environments.
  • Lack of prioritization: Cybersecurity is often not perceived as business-critical.
  • Outdated systems: Older versions of Exchange may no longer be updateable.

The consequences of this negligence can be serious. Unprotected Exchange servers are a popular target for cybercriminals, who can exploit these vulnerabilities to steal sensitive data or launch ransomware attacks.

BSI recommendation for action

The BSI is urging companies and organizations to update their Exchange servers immediately. The following steps are recommended:

  • Instant installation of all available security updates
  • Regularly check patch status
  • Implement additional security measures such as two-factor authentication
  • Consider migrating to cloud-based solutions for better maintainability

 

Recent Posts

Encryption Essentials: What Every Cloud Storage User Should Know

What should we check before trusting important files to the cloud We often treat cloud…

13 hours ago

Operation Bluebird: Twitter is back and controversy is inevitable

The social network Twitter is back in a new form: the US startup Operation Bluebird…

14 hours ago

Xbox Series X25: Price and date of the anniversary console leaked

The new Xbox Series X25 attracts fans with a chic green case in the style…

15 hours ago

Google Search, Discover and News: New options for personalization

Google is expanding personalization for its search, Discover feed and News. A new interactive button…

15 hours ago

GTA 6 leaks: Take-Two goes on a hacker hunt with subpoenas

Take-Two and Rockstar are using all possible means against the attackers operating under the name…

15 hours ago

Exchange Online 2026: Microsoft doubles mailbox storage

Microsoft is doubling the storage space for Exchange Online mailboxes in certain Microsoft 365 Business…

15 hours ago