NSA Warns Of Serious Exploitation Of Microsoft Exchange Server, Here's How To Protect Yourself


The US National Security Agency (NSA as of now) warns of a vulnerability in Microsoft Exchange Server that could allow an attacker with e-mail credentials to launch a remote attack on a target system, allowing it to execute commands. It affects several versions of Microsoft Exchange Server.

"A remote code execution vulnerability exists in Microsoft Exchange Server when the server fails to correctly create unique keys at the time of installation.
Knowledge of a validation key allows an authenticated user with a mailbox to transmit arbitrary objects to be deserialized by the web application, which runs as SYSTEM.
The security update addresses the vulnerability by modifying the way that Microsoft Exchange creates keys during installation, "said Microsoft in a security notice.

Microsoft has released a patch and anyone running an affected version of Microsoft Exchange Server would be wise to install it. Hackers are aware of the vulnerability and seemingly actively exploit the security hole. This is why the NSA has decided to publish a Twitter message reminding users that this vulnerability exists.
Lest anyone forget it, according to a source like the U.S. Department of Defense (DoD) ZDNet that hacking groups targeting this attack vector include "all the big players", although the agency did not name the groups.
This was taken over by the British cybersecurity firm Volexity, which indicated a Zero Day Initiative blog post who emphasized vulnerability. It was not long after the blog post was published that the attacks in the wild began.

"Volexity observed that several APT players were exploiting or attempting to exploit on-premises Exchange servers. In some cases, the attackers appeared to have waited for an opportunity to strike with credentials that otherwise did not exist been of no use. Many organizations use two-factor authentication (2FA) to protect their VPN, email, etc., limiting what an attacker can do with a password. This vulnerability gives attackers the ability to access an important asset within an organization with a simple user ID or an old service. This problem also highlights why changing passwords periodically is a good practice regardless of security measures like 2FA, "says Volexity.

So what can you do? To get started, install the available patch. Volexity also recommends placing Access Control List (ACL) restrictions on the ECP Virtual Director in IIS and / or through any web application firewall capability – only users who specifically need it of an access should have it. This means disabling access from the Internet and restricting IP addresses within an organization.

Activation of 2FA can also serve as a buffer. In addition, periodic updating of passwords is also recommended, "despite various indications about passwords never needing to be changed".

