Microsoft's mitigation for preventing Exchange Server zero-day exploits can be bypassed
Attackers are chaining two vulnerabilities in active attacks to achieve remote code execution on Microsoft Exchange Server
Stay updated with breaking news from Default Web Site. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Attackers are chaining two vulnerabilities in active attacks to achieve remote code execution on Microsoft Exchange Server
Researchers believe Chinese hackers are using them, but mitigations are available.
On September 29, 2022, a Vietnamese cybersecurity firm GTSC, published a blog to expose two zero-day vulnerabilities with Microsoft Exchange Server. These vulnerabilities were actually discovered in early August 2022 by GTSC, who submitted them to the Zero Day Initiative to work with Microsoft to develop necessary patches and mitigation guidance. Typically, these zero-day vulnerabilities... The post Zero-Day Microsoft Exchange Server Vulnerabilities Exposed Early Due to Limited Targeted Attacks appeared first on Pondurance.
While organizations wait for an official patch for the two zero-day flaws in Microsoft Exchange, they should scan their networks for signs of exploitation and apply these mitigations.
Microsoft has issued a security notice about two zero-day vulnerabilities with its own Microsoft Exchange Server. Versions 2013, 2016 and 2019 of the software are affected.