All articles

Action plan for Microsoft Exchange zero-day vulnerabilities

Microsoft Exchange

Important vulnerabilities were recently found in Microsoft Exchange Server. An attacker with SYSTEM privileges can remotely execute arbitrary code using a combination of vulnerabilities. According to the National Cyber Security Centre, there is a high likelihood of exploitation, potentially causing major damage.

  1. Create an inventory
    Do you host an Exchange server locally, on premises?
    Is that Exchange server vulnerable? Most likely, unless you have installed the latest out-of-band updates released by Microsoft on 2 March 2021.
  1. Install the available updates as soon as possible!
    Security updates are available for Exchange Server 2013, 2016 and 2019. More information is available on Microsoft's website.
  1. Scan your Exchange server for malicious web shells
    Use Microsoft's script and the Microsoft Support Emergency Response Tool.
    Even after applying updates, it is important to check whether the vulnerabilities have been exploited. FireEye has observed exploitation of these vulnerabilities since early January 2021.
  1. Monitor your network
    Check whether suspicious or malware activity is occurring on your Exchange servers and endpoints. Check firewall logs for suspicious outgoing traffic.
  1. Reset all accounts as a precaution
    This applies to all user accounts, administrator accounts, service accounts and so on.

If you have run Microsoft's script and there are indications that vulnerabilities have been exploited, malicious actors have had full privileges on the system. It is then highly likely that your network is compromised. Take immediate action! In any case, scan systems connected to the Exchange server with your antivirus software as soon as possible. Use a second virus scanner for another opinion, such as ESET Online.

Commission a Basic Threat Hunt Assessment to check for indications that Exchange zero-day vulnerabilities have been exploited. This assessment thoroughly examines not only the Exchange server itself but also other servers to see whether malware may have been installed and unknown accounts created in the Active Directory environment.

This is an in-depth forensic investigation in which our Threat Hunt team actively scans assets using specialist tools. The results are then analysed by a Threat Intelligence Analyst and documented in a report giving IT managers and security leads an overview of all issues and risks relating to the Microsoft Exchange vulnerabilities. You can see at a glance which problems require an immediate response. The report also provides advice to strengthen the security of your environment.

Our SECWATCH Threat HUNT Team can be reached on 036-5367573 or at threathunt@secwatch.nl. You can also contact us for advice on scanning Exchange servers or analysing the results.

 


Back to all articles