Security News > 2021 > March > Microsoft's GitHub under fire after disappearing proof-of-concept exploit for critical Microsoft Exchange vuln

On Wednesday, shortly after security researcher Nguyen Jang posted a proof-of-concept exploit on GitHub that abuses a Microsoft Exchange vulnerability revealed earlier this month, GitHub, which is owned by Microsoft, removed code, to the alarm of security researchers.
The bug, referred to as ProxyLogon, was one of four Microsoft Exchange zero-days that Microsoft patched in an out-of-band release on March 3, 2021.
Jang posted a write-up of his work, in Vietnamese, with a link to the code on GitHub.
While the PoC code remains accessible in code repos hosted elsewhere, such as competitor GitLab, security researchers have been quick to condemn GitHub for its inconsistent standards and Microsoft for supposed self-interested meddling.
In other words, given how many systems are still vulnerable and under active attack out there, can you really fault Microsoft for trying to limit the spread of exploit code that could be used to bring those installations to their knees?
GitHub did not immediately respond to The Register's request for comment but it defended its actions to Vice by stating that Jang's PoC code pertains to a recently disclosed vulnerability that's being actively exploited.
News URL
https://go.theregister.com/feed/www.theregister.com/2021/03/12/github_disappears_exploit/
Related news
- Microsoft admits GitHub hosted malware that infected almost a million devices (source)
- Microsoft isn't fixing 8-year-old shortcut exploit abused for spying (source)
- Stealthy Apache Tomcat Critical Exploit Bypasses Security Filters: Are You at Risk? (source)
- Microsoft Exchange Online outage affects Outlook web users (source)
- Critical GitHub Attack (source)
- Ongoing Cyber Attacks Exploit Critical Vulnerabilities in Cisco Smart Licensing Utility (source)
- Microsoft: Exchange Online bug mistakenly quarantines user emails (source)
- Android Malware Exploits a Microsoft-Related Security Blind Spot to Avoid Detection (source)
- Microsoft investigates global Exchange Admin Center outage (source)
- Microsoft: Exchange 2016 and 2019 reach end of support in six months (source)