Due to zero-day security vulnerabilities for Microsoft Exchance Server, among others, there is a threat of a new wave of attacks on unpatched Microsoft Exchange servers. Below you will find further background information and information on how to deal with the attack.
What happened?
On November 9, 2021, 55 patches were released for Microsoft, six of which are critical. In February and March, zero-day vulnerabilities in Microsoft Exchange servers were exploited by attackers to gain access to servers. Currently, two zero-day vulnerabilities have been discovered again, one of them for Microsoft Exchange Server.
The CVE-2021-42321 zero-day vulnerability is located in Microsoft Exchange servers and requires immediate action as it is already being actively exploited by attackers. The Perseus cybersecurity team strongly advises you to install the available security patches immediately.
The CVE-2021-42292 vulnerability makes it possible to bypass the security features in Microsoft Excel versions 2013-2021. Attackers could thus install malicious code. All you have to do is get users to download manipulated Excel files – for example, through phishing emails.
CVE-2021-42321: By experts for experts
The CVE-2021-42321 zero-day vulnerability is a critical remote code execution (RCE) vulnerability in Exchange Server caused by issues with the validation of commandlet arguments (cmdlet) – that is, lightweight commands used in the PowerShell environment. They are invoked by the PowerShell runtime in the context of automation scripts deployed from the command line or programmatically invoked by the PowerShell runtime through APIs.
What are the dangers for your company?
The vulnerabilities are already being exploited by cybercriminals. They allow the attackers to implant webshells and perform remote command executions, in short: actively execute commands on the compromised computers to install malware or ransomware and spy on sensitive data. For example, reply emails are sent from personal accounts that contain malicious links.
What can I do?