{"id":462649,"date":"2022-09-30T11:07:54","date_gmt":"2022-09-30T09:07:54","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=462649"},"modified":"2022-09-30T11:11:38","modified_gmt":"2022-09-30T09:11:38","slug":"two-actively-exploited-zero-day-flaws-threaten-microsoft-exchange-servers","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/462649-two-actively-exploited-zero-day-flaws-threaten-microsoft-exchange-servers.html","title":{"rendered":"Two actively exploited zero-day flaws threaten Microsoft Exchange servers"},"content":{"rendered":"<p>Attackers are actively exploiting two flaws in fully patched Microsoft Exchange servers to execute code remotely on affected systems, The Hacker News <strong><a href=\"https:\/\/thehackernews.com\/2022\/09\/warning-new-unpatched-microsoft.html\" target=\"_blank\" rel=\"noopener\">reports<\/a><\/strong>.<\/p>\n<p>The warning came from cybersecurity researchers at the Vietnamese security firm GTSC, who first spotted the vulnerabilities in August 2022.<\/p>\n<p>The Zero Day Initiative <strong><a href=\"https:\/\/www.zerodayinitiative.com\/advisories\/upcoming\/\" target=\"_blank\" rel=\"noopener\">tracks<\/a><\/strong> the two flaws as ZDI-CAN-18333 and ZDI-CAN-18802, which have been assigned Common Vulnerability Scoring System (CVSS) scores of 8.8 and 6.3, respectively.<\/p>\n<p>According to GTSC, exploiting the vulnerabilities could let malicious actors access Microsoft Exchange server systems to drop web shells and carry out lateral movements across the compromised network.<\/p>\n<p>&#8220;We detected webshells, mostly obfuscated, being dropped to Exchange servers,&#8221; it <strong><a href=\"https:\/\/www.gteltsc.vn\/blog\/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html\" target=\"_blank\" rel=\"noopener\">said<\/a><\/strong>.<\/p>\n<p>&#8220;Using the user-agent, we detected that the attacker uses Antsword, an active Chinese-based open source cross-platform website administration tool that supports web shell management.&#8221;<\/p>\n<p>GTSC believes that a Chinese group is likely carrying out attacks as the web shell encoding is in simplified Chinese.<\/p>\n<p>It added that attackers had targeted several organisations by exploiting the two flaws.<\/p>\n<p>The Hacker News provided details on temporary workarounds, including adding a rule to block requests with indicators of compromise through the URL Rewrite Rule Module for IIS servers:<\/p>\n<ul>\n<li>Select the URL Rewrite tab in AutoDiscover at FrontEnd, then select Request Blocking,<\/li>\n<li>Add the string: &#8220;.*autodiscover\\.json.*\\@.*Powershell.*\u201d to the URL path, and<\/li>\n<li>Specify the condition input: Choose {REQUEST_URL}.<\/li>\n<\/ul>\n<p>Cybersecurity researcher Kevin Beaumont <strong><a href=\"https:\/\/doublepulsar.com\/proxynotshell-the-story-of-the-claimed-zero-day-in-microsoft-exchange-5c63d963a9e9\" target=\"_blank\" rel=\"noopener\">explained<\/a><\/strong> that organisations not running Microsoft Exchange on-site, or don&#8217;t have the Outlook Web App facing the Internet, are unaffected.<\/p>\n<hr \/>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/462286-whatsapp-patches-critical-security-flaws.html\" rel=\"bookmark\">WhatsApp patches critical security flaws<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>Vietnamese cybersecurity firm GTSC discovered the two vulnerabilities in August 2022.<\/p>\n","protected":false},"author":341076,"featured_media":449814,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[81707,78704,68902,81709,81376],"class_list":["post-462649","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-gtsc","tag-kevin-beaumont","tag-microsoft-exchange","tag-zero-day-initiative","tag-zero-day-vulnerability"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/462649"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341076"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=462649"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/462649\/revisions"}],"predecessor-version":[{"id":462689,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/462649\/revisions\/462689"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/449814"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=462649"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=462649"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=462649"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}