The German national cybersecurity authority warned on Tuesday that it found at least 17,000 Microsoft Exchange servers in Germany exposed online and vulnerable to one or more critical security vulnerabilities. According to the German Federal Office for Information Security (BSI), around 45,000 Microsoft Exchange servers in Germany have Outlook Web Access (OWA) enabled and are accessible from the Internet. Approximately 12% of these servers still use outdated versions of Exchange (2010 or 2013), which have not received security updates since October 2020 and April 2023, respectively. For the Exchange 2016 or 2019 servers exposed online, roughly 28% have not been patched for at least four months and are vulnerable to at least one critical security flaw exploitable in remote code execution attacks. "Overall, at least 37% of Exchange servers in Germany (and in many cases also the networks behind them) are severely vulnerable. This corresponds to approx. 17,000 systems. In particular, many schools and colleges, clinics, doctor's offices, nursing services and other medical institutions, lawyers and tax consultants, local governments, and medium-sized companies are affected," the BSI warned [PDF]. "As early as 2021, the BSI warned several times against the active exploitation of critical vulnerabilities in Microsoft Exchange and temporarily called the IT threat situation 'red.' Nevertheless, the situation has not improved since then, as many Exchange server operators continue to ac...
Germany warns of 17K vulnerable Microsoft Exchange servers exposed online
BleepingComputer
·Sergiu Gatlan
·Published Mar 26, 2024
·Updated
Affected Software
4 affected components
Microsoft Exchange=2010
Microsoft Exchange=2013
Microsoft Exchange=2016
Microsoft Exchange=2019
Frequently Asked Questions
1
What is the main concern raised by Germany's cybersecurity authority?
The main concern is the discovery of at least 17,000 Microsoft Exchange servers in Germany that are exposed online and vulnerable to critical security issues.
2
What are the specific Microsoft Exchange versions identified as vulnerable?
The affected Microsoft Exchange versions include 2010, 2013, 2016, and 2019.
3
What critical risks do these vulnerabilities pose to the exposed servers?
These vulnerabilities could potentially allow unauthorized access, data breaches, and exploitation by cybercriminals.
4
What actions should organizations take in response to these vulnerabilities?
Organizations should immediately assess their systems, apply security updates, and implement proper security measures to mitigate risks.
5
Is the issue limited to Germany, or could it be a global concern?
While the warning is specific to Germany, the issue of vulnerable Microsoft Exchange servers could impact organizations globally.