Microsoft has released some urgent security updates for all supported versions of Microsoft Exchange, which fix four zero-day vulnerabilities that are actively being exploited in targeted attacks.
These four zero-day vulnerabilities are linked together to gain access to Microsoft Exchange servers, steal emails, and install further malware for increased network access.

For the attack to work, remote attackers would need to have access to an on-premises Microsoft Exchange server on port 443. If access is available, threat actors would then exploit the following vulnerabilities to gain remote access:
- CVE-2021-26855 is a server-side request forgery (SSRF) vulnerability in Exchange, which allowed an attacker to send arbitrary HTTP requests and authenticate as an Exchange server.
- CVE-2021-26857 is a critical deserialization vulnerability in the Unified Messaging service. Exploiting this vulnerability allowed the HAFNIUM team to execute code as SYSTEM on the Exchange server. This requires administrator permission or another vulnerability to exploit.
- CVE-2021-26858 is a vulnerability that allows arbitrary file writing after authentication in Exchange.
- CVE-2021-27065 is a vulnerability that allows arbitrary file writing after authentication in Exchange.
Microsoft has identified that a Chinese state-run hacking group known as Hafnium is using these vulnerabilities to steal data.
Due to the severity of the attacks, Microsoft recommends that administrators “immediately install these updates” to protect Exchange servers from these attacks.
Microsoft Senior Threat Intelligence Analyst Kevin Beaumont has created an Nmap script that can be used to scan a network for potentially vulnerable Microsoft Exchange servers.
To use the script, download it from the GitHub page and save it to /usr/share/nmap/scripts, then use the command nmap –script http-vuln-exchange.

Once you have determined which Exchange servers need to be updated, you must ensure that your servers have a current supported cumulative update (CU) and rollup (RU) installed.
Administrators can find more information about supported updates and how to install the patches in an article published today by the Microsoft Exchange team.
Information source: bleepingcomputer.com
