NEW EXCHANGE SERVER VULNERABILITIES

April 14, 2021

Microsoft has just released security updates for Exchange Server that address a set of four vulnerabilities, classed as high to critical importance.

Microsoft credited the NSA for finding two remote code execution vulnerability flaws (CVE-2021-28480 and CVE-2021-28481) in Exchange Server. Both bugs found by the NSA carry a CVSS score of 9.8 due to the risks of attacks without user interaction.

The flaws affect on-premise Exchange Server versions 2013 through 2019 and while there is no evidence of being exploited in the wild, Microsoft assesses that threat actors are likely to leverage them as soon as they create an exploit.

The NSA says that the discovery of critical vulnerabilities in the Microsoft Exchange server is recent and that they reported them immediately.

This is the second serious attack on Microsoft Exchange Servers in recent months and is a major headache for Microsoft and their clients using on-premise Exchange servers. Microsoft released emergency patches for Microsoft Exchange Server 2013, Exchange Server 2016, and Exchange Server 2019 on March 2. At the time, the company said that four zero-day vulnerabilities which could lead to data theft and overall server hijacking were being actively exploited in “limited, targeted attacks.”

However, it was not long before multiple advanced persistent threat (APT) groups began to join in Exchange Server-based campaigns and it is estimated that thousands of systems belonging to organizations worldwide have been compromised.

As always, Integrity IT Solutions constantly monitor threats and have already been in touch with all of our clients who are affected.

SHARE


April 23, 2025
At Integrity IT, part of the Eco group of businesses, we believe that when you invest in people, you build a stronger business. That’s why we’re proud to share two well-earned internal promotions that reflect the continued growth and evolution of our team.
April 23, 2025
On 21/04/2025, Marks and Spencer (M&S) confirmed it was managing a cyber incident that disrupted contactless payments and delayed online order collections.
By Eddie Black February 19, 2024
INTEGRITY IT Solutions has strengthened its team following a successful restructuring of the business.
Leading IT specialists Integrity IT Solutions are supporting schools to achieve faster broadband.
By Eddie Black January 19, 2024
A LEADING IT company is offering schools and colleges a free review of their broadband connectivity to help them achieve targets for faster internet speeds as outlined in the latest Government’s guidelines.
By Eddie Black June 1, 2023
With ever-increasing pressures on businesses to achieve net zero, Gary Robertson, from EcoGoZero, explains why collaboration is key.
SHOW MORE