HomeSecurity80% of Microsoft Exchange Servers have not received a patch for a critical bug!

80% of Microsoft Exchange Servers have not received a patch for a critical bug!

Microsoft has recently patched a critical remote code execution vulnerability in Microsoft Exchange Server. This vulnerability allows hackers to use Exchange user accounts to compromise the system. Specifically, the vulnerability is located in the Exchange Control Panel (ECP), which can be used to manage mailboxes , distribution groups, mailbox contacts, and other organizational-level objects. According to research conducted by Rapid 7 with Project Sonar, over 350,000 Exchange Servers that were affected by this vulnerability were exposed online. Project Sonar is a tool used by the security firm to conduct online research into various services and protocols in order to identify potential vulnerabilities.

80% of Microsoft Exchange Servers have not received a patch for a critical bug!

The results of the investigation conducted by Rapid 7 with Project Sonar showed that more than 430,000 Exchange Servers were found to be online ,while at least 360,000 of them, or about 82.5%, were experiencing an error. The company said that the remote and uncertified inspection does not provide precise details about these findings and therefore cannot be completely sure of the results. It also pointed out that the relevant security from Microsoft does not always update the build number, which leads to uncertainty. The company also said that more than 30,000 Exchange Servers 2010 have not been updated since 2012, while 800 Exchange Servers have never received an update.


Many APT hackers are already attempting to exploit a remote code execution flaw that was discovered in Exchange email servers and recently patched. According to Microsoft, the flaw was due to a memory corruption vulnerability in Microsoft Exchange, which could be exploited by hackers to send malicious emails to vulnerable Exchange Servers. Microsoft patched the vulnerability in February 2020, recommending that users apply the appropriate updates to address it.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS