Security News > 2021 > March > Microsoft: Chinese Cyberspies Used 4 Exchange Server Flaws to Plunder Emails
Microsoft Corp. today released software updates to plug four security holes that attackers have been using to plunder email communications at companies that use its Exchange Server products.
The patches released today fix security problems in Microsoft Exchange Server 2013, 2016 and 2019.
Microsoft says the flaws are being used by a previously unknown Chinese espionage group that's been dubbed "Hafnium," which is known to launch its attacks using hosting companies based in the United States.
According to Microsoft, Hafnium attackers have been observed combining all four zero-day flaws to target organizations running vulnerable Exchange Server products.
The attackers used CVE-2021-26857 to run code of their choice under the "System" account on a targeted Exchange server.
Microsoft technical advisory on the four Exchange Server flaws.
News URL
Related news
- Microsoft Exchange adds warning to emails abusing spoofing flaw (source)
- Microsoft fixes Outlook email sending issue for users with many folders (source)
- Critical Zimbra RCE flaw exploited to backdoor servers using emails (source)
- Over 5,000 Fake Microsoft Notifications Fueling Email Compromise Campaigns (source)
- Microsoft fixes Remote Desktop issues caused by Windows Server update (source)
- Microsoft Detects Growing Use of File Hosting Services in Business Email Compromise Attacks (source)
- Microsoft Outlook bug blocks email logins, causes app crashes (source)
- Microsoft deprecates PPTP and L2TP VPN protocols in Windows Server (source)
- Microsoft: Chinese hackers use Quad7 botnet to steal credentials (source)
- Microsoft Warns of Chinese Botnet Exploiting Router Flaws for Credential Theft (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-03-03 | CVE-2021-26857 | Deserialization of Untrusted Data vulnerability in Microsoft Exchange Server Microsoft Exchange Server Remote Code Execution Vulnerability | 7.8 |