State-sponsored Attackers Exploit Zero-day Microsoft Exchange Vulnerabilities

Date:

Share post:

Security experts from Volexity discovered state-sponsored hacking groups exploiting just patched critical Microsoft Exchange bugs from January 6, 2021. The technology giant recently addressed four Zero-day vulnerabilities (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) and three other vulnerabilities (CVE-2021-27078, CVE-2021-26854, and CVE-2021-26412) in its Patch Tuesday security update.

Volexity claimed that threat actors were exploiting the CVE-2021-26855 Microsoft Exchange Server vulnerability in their ongoing attacks to obtain remote code execution on vulnerable Exchange servers. Volexity identified a massive amount of information being transferred from the Exchange servers to unknown IP addresses legitimate users.

“The logs showed inbound POST requests to valid files associated with images, JavaScript, cascading style sheets, and fonts used by Outlook Web Access (OWA). It was initially suspected the servers might be backdoored and that webshells were being executed through a malicious HTTP module or ISAPI filter. This investigation revealed that the servers were not backdoored and uncovered a zero-day exploit being used in the wild,” Volexity said.

Volexity’s researchers found that the attackers were exploiting a zero-day server-side request forgery (SSRF) to steal the entire contents of several user mailboxes. As the CVE-2021-26855 vulnerability is remotely exploitable, an attacker does not require any kind of authentication or access to a target environment.

Indicators of Compromise

/owa/auth/Current/themes/resources/logon.css
/owa/auth/Current/themes/resources/owafont_ja.css
/owa/auth/Current/themes/resources/lgnbotl.gif
/owa/auth/Current/themes/resources/owafont_ko.css
/owa/auth/Current/themes/resources/SegoeUI-SemiBold.eot
/owa/auth/Current/themes/resources/SegoeUI-SemiLight.ttf
/owa/auth/Current/themes/resources/lgnbotl.gif

Volexity urged organizations and users to apply the available security patches or temporarily disable external access to Microsoft Exchange as early as possible.

“Highly skilled attackers continue to innovate to bypass defenses and gain access to their targets, all in support of their mission and goals. These vulnerabilities in Microsoft Exchange are no exception. These attackers are conducting novel attacks to bypass authentication, including two-factor authentication, allowing them to access e-mail accounts of interest within targeted organizations and remotely execute code on vulnerable Microsoft Exchange servers,” Volexity added.

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

5th Edition MENA CYBER SECURITY CONFERENCE – RIYADH EDITION

Name: 5th Edition MENA CYBER SECURITY CONFERENCE - RIYADH EDITION Website: https://mena-cybersecurity.com/riyadh/ Date: September 8th, 2026 Location: Crowne Plaza Riyadh Palace,...

Cyber Security Expo

Name: Cyber Security EXPO Website: https://www.cybersecurityexpo.co.uk/cheltenham Date: September 10, 2026 Location: Cheltenham Racecourse, United Kingdom The Cyber Security EXPO is the only...

6th Edition MENA CISO SUMMIT – Dubai Edition

Name: 6th Edition MENA CISO Summit – Dubai Edition Website: https://mena-cybersecurity.com/ciso-dubai/ Date: September 30, 2026 Location: Millennium Airport Hotel, Dubai,...

Build the Pipeline, Not the Headcount

There's a principle in Taoist philosophy called wu wei, often translated as "effortless action" or "non-doing." It doesn't...