🟠High: Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
-
Nearly 22,000 internet-exposed Microsoft Exchange servers are still running unpatched builds, leaving them open to a high-severity authentication bypass that can let an attacker take over every mailbox on the system. The flaw allows remote exploitation without valid credentials, effectively granting full control over user accounts and mail data.
The vulnerable versions remain exposed despite patches being available for some time. Administrators are urged to check their Exchange Server builds against the latest cumulative updates, as the attack vector does not require any user interaction. Successful exploitation can lead to data theft, mailbox hijacking, and further lateral movement inside a corporate network.
- Affected component: Exchange Server authentication mechanism
- Impact: Full mailbox takeover, unauthorized access to emails and attachments
- Attack vector: Remote, unauthenticated
Mitigation steps include:
- Apply the latest Exchange Server cumulative updates immediately
- Verify no unknown or rogue accounts have been added since exposure
- Review IIS logs for suspicious authentication entries or anomaly patterns
- Restrict remote access to Exchange endpoints where possible
If patching is not immediately feasible, administrators should consider placing Exchange servers behind a VPN or additional access controls to reduce exposure.
Source: Unknown
Is your organization among the exposed instances, and are you prioritizing the patch rollout or adding temporary access restrictions first?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login