Hackers are looking for Microsoft Exchange Servers that are vulnerable to the remote code execution flaw CVE-2020-0688, for which Microsoft released patches a while ago. All versions of Exchange Server up to the latest patch are likely to be attacked after these ongoing hacker scans, including those that are not currently supported. The flaw exists in the Exchange Control Panel (ECP) and is caused by Exchange’s inability to generate unique cryptographic “keys” during its installation. This flaw allows authenticated attackers to remotely execute code with SYSTEM privileges on a server and compromise it to be able to manage it as they wish.
Zero Day Initiative security researcher Simon Zuckerbraun has released a demo showing how someone can exploit the CVE-2020-0688 vulnerability in Microsoft Exchange and use the fixed cryptographic “keys” to compromise an unpatched server. Zuckerbraun explains that any external attacker who compromises the device or credentials of any business user could take control of the Exchange server. If they can do this, the attacker would be able to reveal or falsify the communications that a business makes via email . Those who manage the Exchange Server should take note that this is a critical flaw. Although Microsoft has rated the CVE-2020-0688 vulnerability as critical, if a hacker from inside or outside an organization manages to change the credentials of any user , they will likely be able to access and manage the Exchange server.
It should be noted, however , that a hacker can only exploit this flaw on vulnerable servers that have Internet access and can look up email addresses collected from the Outlook Web Access (OWA) portal URL . They can then compromise credentials until they have a chance to log in to the server. Once they are logged in, all they have to do is exploit the CVE-2020-0688 flaw and gain control of the targeted Exchange server.
Microsoft expects exploits to occur within 30 days of the patch release. The mass attacks target unpatched Microsoft Exchange Servers to inject ransomware payloads and other dangerous malicious content. Finally, according to Microsoft, since there are no mitigations or even prevention measures available, the only thing users can do is patch their servers before hackers reach them.
