A few days ago, two zero-day vulnerabilities were discovered in Microsoft Exchange Server 2013, 2016, and 2019. Microsoft has now confirmed that the vulnerabilities are currently being exploited by attackers in the wild. Remedial measures are available, but a proper fix is not yet.
The Microsoft Security Response Center has been there since yesterday’s entry, which provides an update on the investigation into two major vulnerabilities in Exchange. First of all, Microsoft once again lists the corresponding codes for the Common Vulnerabilities and Exposures (CVE) catalog and the known attack vectors:
This is followed by a clear warning from the security researchers: “Microsoft is currently aware of a number of targeted attacks in which the two security vulnerabilities are exploited in order to penetrate users’ systems.” However, the company also emphasizes that “authenticated access” to the vulnerable Exchange Server is required to successfully exploit either vulnerability.
According to Microsoft, they are currently working on an “accelerated schedule” for the release of the necessary error corrections, but cannot yet give a date when the fix can be expected.
In order for customers to be able to protect themselves from possible attacks by then, reference is made to instructions for preliminary remedial measures. In order to apply the protective measures to vulnerable servers, the following steps are necessary:
Also, Microsoft’s administrators advise blocking the following remote PowerShell ports to prevent the attacks:
Digital marketing enthusiast and industry professional in Digital technologies, Technology News, Mobile phones, software, gadgets with vast experience in the tech industry, I have a keen interest in technology, News breaking.
Multikernel Technologies has a public version of its multikernel Linux for the first time with…
The world's PC manufacturers are in a bind when it comes to memory. DDR4 RAM…
How safe are the protected halls of Gamescom 2026 really? After the night-time theft of…
Google has apparently made changes to the security features of the Pixel 11 series, which…
Bagging a bargain online has never been easier - or riskier. Between dodgy "influencer" deals…
Google is expanding its AI overviews and is now displaying even more information and details…