Security News > 2021 > March > Microsoft Shares Additional Mitigations for Exchange Server Vulnerabilities Under Attack

Microsoft Shares Additional Mitigations for Exchange Server Vulnerabilities Under Attack
2021-03-06 15:30

Microsoft on Friday released alternative mitigation measures for organizations who have not been able to immediately apply emergency out-of-band patches released earlier this week that address vulnerabilities being exploited to siphon e-mail data from corporate Microsoft Exchange servers.

"These mitigations are not a remediation if your Exchange servers have already been compromised, nor are they full protection against attack," Microsoft warned in a blog post.

Security researchers have warned that multiple cyber-espionage groups have been targeting vulnerable Exchange servers.

The U.S. Cybersecurity and Infrastructure Security also issued an alert Friday, urging organizations to upgrade their on-premises Microsoft Exchange servers to the latest supported version.

Cybersecurity firm Volexity, which was credited by Microsoft for reporting different parts of the attack chain, has published a blog post with technical details and a video demonstrating exploitation in action, along with known attacker IP addresses connected to the attacks.

Volexity said it detected anomalous activity from two of its customers' Microsoft Exchange servers in January 2021, which led to discovery of the attacks.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/IihaWmU26H4/microsoft-shares-additional-mitigations-exchange-server-vulnerabilities-under-attack

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 480 75 2308 5127 264 7774