Hackers are Scanning for Unpatched Exchange Servers Flaws

2 years ago 146
BOOK THIS SPACE FOR AD
ARTICLE AD

15. August 2021

This article has been indexed from Softpedia News / Security

Microsoft Exchange servers are targeted again this time via a chain of three different vulnerabilities that affect on-premises installations, according to The Hacker News.

Known as ProxyShell, the three vulnerabilities in question can be exploited to allow remote code execution, elevate privileges on the Exchange PowerShell backend, effectively authenticate the attacker, and bypass access control lists (ACLs) on the victim’s system.

The vulnerability is tracked as CVE-2021-26855 (ProxyLogon) for server-side request forgery in Exchange Server and serves as an entry point to gain complete control of a vulnerable server. In conjunction with CVE-2021-27065, it can be used to execute code on the server. 

Microsoft disclosed the flaws after revealing a …

Read the original article: Hackers are Scanning for Unpatched Exchange Servers Flaws

Read Entire Article