In early March, zero-day vulnerabilities affecting Microsoft Exchange were publicly disclosed. These vulnerabilities were actively exploited in the wild by Hafnium, a threat actor believed to be a nation state. According to an alert from the CISA:CISA issued an emergency directive urging organizations to patch on-premises Exchange Servers while performing associated security scans to see if attackers are in the systems. Unfortunately, many organizations have still neglected to patch their systems and as a result, other cybercriminals have since taken advantage of vulnerable Exchange servers to launch attacks such as DearCry and Black Kingdom ransomware, as well as using the compromised servers for cryptomining.
Guest blog courtesy of at Sophos. Read more Sophos blogs here.
“Microsoft has released out-of-band security updates to address vulnerabilities affecting Microsoft Exchange Server 2013, 2016, and 2019. A remote attacker can exploit three remote code execution vulnerabilities—CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065—to take control of an affected system and can exploit one vulnerability—CVE-2021-26855—to obtain access to sensitive information. These vulnerabilities are being actively exploited in the wild.”
Tips for Partners to Protect their Customers
First and foremost, partners and MSPs can and should play a key role in making sure customers are patching all on-premise Microsoft Exchanged servers in their environments with the relevant security update. Details can be found on Microsoft’s Exchange Team blog. However, it is important to note that even with the patches installed, this will not address the presence of any malicious web shells.If a customer believes their organizations has been exposed, MSPs should consult the Sophos MTR team’s step-by-step guide on how to search a customer’s network for signs of compromise. After patching or disabling servers that could potentially be exploited, Sophos recommends:- Determining possible exposure Download and run the Test-ProxyLogon.ps1 script provided by the Microsoft Customer Support Services team
- Looking for web shells or other suspicious .aspx files
- Using a query to identify potential web shells to investigate, check patch level of your servers, and look for suspicious commands
- Establishing impact by Review process activity and command executions from the time the web shell was created, onwards




