Update 26.3.2024: While not on the same scale as 2021's Microsoft Exchange Server hack (see below this update), security problems impacting Exchange Server have reemerged. In March 2024's monthly patch cycle, Microsoft resolved critical issues in software including HyperV and Exchange Server. These fixes follow the release of a 2024 H1 Cumulative Update for Exchange Server in February. The 2024 H1 Cumulative Update includes Extended Protection (EP) being enabled by default. EP is a Windows feature for protecting servers from man-in-the-middle (MiTM) attacks. The automatic inclusion of EP was first announced in 2023. Also: The best VPN services of 2024: Expert tested and reviewed The security upgrade can help resolve CVE-2024-21410, a privilege escalation vulnerability leading to NTLM relay attacks that impacts Exchange Server. This vulnerability is being actively exploited in the wild. "An attacker could target an NTLM client such as Outlook with an NTLM credentials-leaking type vulnerability," Microsoft says. "The leaked credentials can then be relayed against the Exchange server to gain privileges as the victim client and to perform operations on the Exchange server on the victim's behalf." CVE-2024-21410 was revealed in the February 2024 Microsoft patch update. Original article, first published in 2021: Four zero-day vulnerabilities in Microsoft Exchange Server are being actively exploited by state-sponsored threat groups and others to deploy backdoors and malware in wides...
Everything you need to know about the Microsoft Exchange Server hack
ZDNet
·Charlie Osborne
·Published Mar 26, 2024
·Updated
Affected Software
7 affected components
Microsoft Exchange Server
Microsoft HyperV
Microsoft Exchange Server=2013
Microsoft Exchange Server=2016
Microsoft Exchange Server=2019
Microsoft Exchange Server=2010
Microsoft Exchange Online
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the recent security vulnerabilities affecting Microsoft Exchange Server and other related Microsoft products.
2
What security implications are discussed in the article?
The article highlights new security threats and the importance of timely patching to protect against these vulnerabilities.
3
What products or software are affected by the vulnerabilities mentioned?
The affected software includes Microsoft Exchange Server versions 2010, 2013, 2016, 2019, Microsoft Exchange Online, and Microsoft Hyper-V.
4
How severe are the security issues mentioned in the article compared to previous incidents?
While the issues are serious, they are noted to be on a smaller scale compared to the significant Microsoft Exchange Server hack of 2021.
5
What actions does Microsoft recommend to mitigate these security risks?
Microsoft recommends applying the latest patches as part of the monthly patch cycle to address the vulnerabilities.