Microsoft Exchange servers vulnerable

28,500 Microsoft Exchange servers have now been confirmed to be vulnerable to elevation of privilege. This puts affected organizations worldwide at significant risk, as many users are connected to Exchange for work.

The attack surface may be even larger. In fact, the threat monitoring service Shadowserver has 97,000 servers identified as ‘potentially vulnerable. This depends on the measures administrators have taken. Shadowserver has no visibility into whether these 68,500 potentially vulnerable servers have been patched, but again refers to the Microsoft documentation.

With just over 3,000 cases, the Netherlands is among the hardest hit countries. Belgium is less affected, with about 1,000 servers. Germany tops the list by far, with nearly 23,000 Shadowserver reports.

At issue is an elevation of privilege (EoP) vulnerability in Exchange Server. The bug allows a cybercriminal to pass a leaked Net-NTLMv2 hash to a vulnerable Exchange server to authenticate as that user. Hackers could potentially crack NTLM hashes or deploy an NTLM relay attack.

“An attacker can target an NTLM client, such as Outlook, with an NTLM data leakage vulnerability type,” said Microsoft in warning. The leaked login credentials allow malicious actors to gain additional privileges in the network and attack targets from the Exchange Server.

Solution

Until now, Exchange Server did not have relay protection enabled by default for NTLM credentials. Microsoft is now going to change that, by enabling so-called Extended Protection (EP) by default on all Exchange Servers. This will require installing the 2024 H1 Cumulative Update.

Of course we take care of this for you, super logical for us! Do you need help, or do you want to know if your organization's exchange server is secure please take a moment contact with us.

Source: technzine

Recent blogs

apple header
Blog
Apple 50 Years: 50 Years of Daring to Think Differently
This year, Apple celebrates its 50th anniversary. A milestone that cannot simply be overlooked. Because whether you are a fan or not: Apple has permanently changed the way we work, communicate, and create. At Analyst ICT, we are proud to be part of this ecosystem. As an Apple Technical Partner, we work daily with technology that is not only powerful but, above all, logical and pleasant to use. A different perspective on technology Apple has always distinguished itself by one simple conviction: technology should help people, not hinder them. No unnecessary complexity, but simplicity and ease of use. That aligns seamlessly...
browser password
Blog
Why saving passwords in your browser is not a good idea
The blog post below was created in response to a question during our engineering meeting. Every two weeks, we get together with all of our technical staff to discuss the latest developments in technology or with clients. Good client questions also arise during these meetings, such as this one. Time to do some research. Thank you, Wiebe! You've probably experienced this: you log in to a website, and your browser asks if it should remember your password. Convenient, fast, and you don't have to remember anything. However, there's a risk involved. In practice, we see that many security incidents start with something small. Like saving passwords…
Apple Business
Blog
Apple is taking a big step with Apple Business
Apple announced something special this week. Not a new device, but something that might be even more interesting for many organizations: Apple Business. A completely new platform with which Apple brings all its business services together in one environment. And frankly: this is a development that we at Analyst ICT are following with great interest. The problem: fragmented tools and unnecessary complexity Many organizations working with Apple will recognize the problem: Multiple portals (Apple Business Manager, Business Essentials, Connect) Different tools for management, branding, and support Additional costs for basic functionalities such as device management This leads to a lack of clarity and costs time. And…

A newsletter

Superlogic right?