Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On March 2, 2021, Microsoft disclosed four zero-day vulnerabilities being exploited against on-premises Exchange Server. Microsoft attributed the initial campaign with high confidence to HAFNIUM, a state-sponsored group it assessed as operating from China. Exchange Online was not affected by this incident.

What happened in the Exchange Server attack?

The vulnerabilities affected on-premises Microsoft Exchange Server and could be chained to gain access, execute code, and write files to a server. Attackers commonly installed web shells after exploiting a server. A web shell can provide a way to run commands and maintain access, and can be used for data theft or movement to other systems on a network.

Microsoft disclosed the campaign on March 2, 2021, and named four vulnerabilities: CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. Microsoft’s Tom Burt, Corporate Vice President for Customer Security & Trust, said, “Promptly applying today’s patches is the best protection against this attack.”

Which Exchange servers were affected?

The affected products were on-premises Exchange Server 2010, 2013, 2016, and 2019. Exchange Online was not affected by this 2021 incident. Microsoft specifically noted that Exchange Server 2010 was affected by CVE-2021-26857, a flaw that was not the first step in the attack chain.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The HAFNIUM attribution applies to Microsoft’s assessment of the initial campaign. It should not be taken to mean that HAFNIUM was responsible for all later attacks using the vulnerabilities.

How did the four vulnerabilities work together?

  • CVE-2021-26855: A server-side request forgery (SSRF) flaw. It let an unauthenticated attacker send arbitrary HTTP requests and authenticate to Exchange.
  • CVE-2021-26858 and CVE-2021-27065: Post-authentication flaws that enabled arbitrary file writes.
  • CVE-2021-26857: An insecure deserialization flaw that could enable arbitrary code execution as SYSTEM.

In a common sequence, an attacker used CVE-2021-26855 to gain a foothold, then exploited one or more of the other flaws to write files or execute code. Installing a web shell could then provide persistence and a route to command execution, data theft, or lateral movement.

When did the attacks happen, and did they spread?

Microsoft disclosed the campaign on March 2, 2021. The U.S. Department of Justice later said groups had exploited the flaws during January and February, before the public disclosure. After the vulnerabilities and patches became public in early March, additional groups also exploited them. By the end of March, hundreds of web shells remained on some U.S.-based Exchange computers, according to the Department of Justice.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should administrators respond?

1. Patch the Exchange server

Move to a supported Exchange cumulative update and apply all security updates. Microsoft described this as the strongest and most complete mitigation. Temporary mitigations and exposure restrictions do not replace patching.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Reduce exposure if patching is delayed

Microsoft’s Exchange On-Premises Mitigation Tool (EOMT.ps1) or ExchangeMitigations.ps1 can provide temporary measures. Restricting inbound port 443 or limiting exposure of Outlook on the web (OWA) and the Exchange Control Panel (ECP) can also reduce risk temporarily. Treat these as interim steps, not a fix.

3. Check for signs of exploitation

Use Microsoft Defender for Endpoint or Microsoft’s published Nmap and Test-ProxyLogon workflows to check for indicators. Also investigate Exchange web-server directories for newly created or modified ASPX files and review logs for activity associated with each of the four CVEs. Finding or removing a web shell is not, by itself, proof that the server is clean.

4. Investigate and recover beyond the Exchange server

If you find evidence of exploitation, CISA advises assuming that network identities may be compromised and following incident-response procedures. Investigate and address web shells and other persistence, exposed credentials, Active Directory, and possible lateral movement. The Department of Justice later said its FBI operation removed identified web shells, but did not patch the servers or guarantee that other malware had been removed; a full investigation is therefore necessary.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.