https://www.bleepingcomputer.com/news/security/new-microsoft-exchange-zero-days-actively-exploited-in-attacks/ BleepingComputer.com logo * * * [ ] [Login] [Sign up] * * * [ ] [Login] [Sign up] * News + Featured + Latest + Microsoft confirms new Exchange zero-days are used in attacks Microsoft confirms new Exchange zero-days are used in attacks + Windows 11 22H2 blocked on some systems due to printer issues Windows 11 22H2 blocked on some systems due to printer issues + New malware backdoors VMware ESXi servers to hijack virtual machines New malware backdoors VMware ESXi servers to hijack virtual machines + Hacking group hides backdoor malware inside Windows logo image Hacking group hides backdoor malware inside Windows logo image + Microsoft to let Office 365 users report Teams phishing messages Microsoft to let Office 365 users report Teams phishing messages + Lazarus hackers abuse Dell driver bug using new FudModule rootkit Lazarus hackers abuse Dell driver bug using new FudModule rootkit + Learn the A-to-Z's of ethical hacking in 18 online courses for $43 Learn the A-to-Z's of ethical hacking in 18 online courses for $43 + Windows 11 22H2 KB5017389 preview update released with 30 changes Windows 11 22H2 KB5017389 preview update released with 30 changes * Downloads + Latest + Most Downloaded + Qualys BrowserCheck Qualys BrowserCheck + STOPDecrypter STOPDecrypter + AuroraDecrypter AuroraDecrypter + FilesLockerDecrypter FilesLockerDecrypter + AdwCleaner AdwCleaner + ComboFix ComboFix + RKill RKill + Junkware Removal Tool Junkware Removal Tool * Virus Removal Guides + Latest + Most Viewed + Ransomware + Remove the Theonlinesearch.com Search Redirect Remove the Theonlinesearch.com Search Redirect + Remove the Smartwebfinder.com Search Redirect Remove the Smartwebfinder.com Search Redirect + How to remove the PBlock+ adware browser extension How to remove the PBlock+ adware browser extension + Remove the Toksearches.xyz Search Redirect Remove the Toksearches.xyz Search Redirect + Remove Security Tool and SecurityTool (Uninstall Guide) Remove Security Tool and SecurityTool (Uninstall Guide) + How to remove Antivirus 2009 (Uninstall Instructions) How to remove Antivirus 2009 (Uninstall Instructions) + How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo + How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller + Locky Ransomware Information, Help Guide, and FAQ Locky Ransomware Information, Help Guide, and FAQ + CryptoLocker Ransomware Information Guide and FAQ CryptoLocker Ransomware Information Guide and FAQ + CryptorBit and HowDecrypt Information Guide and FAQ CryptorBit and HowDecrypt Information Guide and FAQ + CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ * Tutorials + Latest + Popular + How to open a Windows 11 Command Prompt as Administrator How to open a Windows 11 Command Prompt as Administrator + How to make the Start menu full screen in Windows 10 How to make the Start menu full screen in Windows 10 + How to install the Microsoft Visual C++ 2015 Runtime How to install the Microsoft Visual C++ 2015 Runtime + How to open an elevated PowerShell Admin prompt in Windows 10 How to open an elevated PowerShell Admin prompt in Windows 10 + How to start Windows in Safe Mode How to start Windows in Safe Mode + How to remove a Trojan, Virus, Worm, or other Malware How to remove a Trojan, Virus, Worm, or other Malware + How to show hidden files in Windows 7 How to show hidden files in Windows 7 + How to see hidden files in Windows How to see hidden files in Windows * Deals + Categories + eLearning eLearning + IT Certification Courses IT Certification Courses + Gear & Gadgets Gear + Gadgets + Security Security * Forums * More + Startup Database + Uninstall Database + Glossary + Chat on Discord + Send us a Tip! + Welcome Guide * Home * News * Security * New Microsoft Exchange zero-days actively exploited in attacks * * New Microsoft Exchange zero-days actively exploited in attacks By Sergiu Gatlan * September 29, 2022 * 05:52 PM * 4 Microsoft Exchange Threat actors are exploiting yet-to-be-disclosed Microsoft Exchange zero-day bugs allowing for remote code execution, according to claims made by security researchers at Vietnamese cybersecurity outfit GTSC, who first spotted and reported the attacks. Friday morning, Microsoft confirmed the two new zero-day vulnerabilities are being used in attacks and are tracked as CVE-2022-41040 and CVE-2022-41082. They also confirmed that GTSC' mitigations (shared below) are successful in blocking the attacks. The attackers are chaining the pair of zero-days to deploy Chinese Chopper web shells on compromised servers for persistence and data theft, as well as move laterally to other systems on the victims' networks. "The vulnerability turns out to be so critical that it allows the attacker to do RCE on the compromised system," the researchers said. GTSC suspects that a Chinese threat group is responsible for the attacks based on the web shells' code page, a Microsoft character encoding for simplified Chinese. The user agent used to install the web shells also belongs to Antsword, a Chinese-based open-source website admin tool with web shell management support. Microsoft hasn't disclosed any information regarding the two security flaws so far and is yet to assign a CVE ID to track them. The researchers reported the security vulnerabilities to Microsoft privately three weeks ago through the Zero Day Initiative, which tracks them as ZDI-CAN-18333 and ZDI-CAN-18802 after its analysts validated the issues. "GTSC submitted the vulnerability to the Zero Day Initiative (ZDI) right away to work with Microsoft so that a patch could be prepared as soon as possible," they added. "ZDI verified and acknowledged 2 bugs, whose CVSS scores are 8.8 and 6.3." Trend Micro released a security advisory Thursday evening confirming that they submitted the two new Microsoft Exchange zero-day vulnerabilities discovered by GTSC to Microsoft. The company has already added detections for these zero-days to its IPS N-Platform, NX-Platform, or TPS products. There's reports emerging that a new zero day exists in Microsoft Exchange, and is being actively exploited in the wild I can confirm significant numbers of Exchange servers have been backdoored - including a honeypot. Thread to track issue follows: -- Kevin Beaumont (@GossiTheDog) September 29, 2022 GTSC has released very few details regarding these zero-day bugs. Still, its researchers did reveal that the requests used in this exploit chain are similar to those used in attacks targeting the ProxyShell vulnerabilities. The exploit works in two stages: 1. Requests with a similar format to the ProxyShell vulnerability: autodiscover/autodiscover.json?@evil.com/ &Email=autodiscover/ autodiscover.json%3f@evil.com. 2. The use of the link above to access a component in the backend where the RCE could be implemented. "The version number of these Exchange servers showed that the latest update had already installed, so an exploitation using Proxyshell vulnerability was impossible," the researchers said. Temporary mitigation available Until Microsoft releases security updates to address the two zero-days, GTSC shared temporary mitigation that would block attack attempts by adding a new IIS server rule using the URL Rewrite Rule module: 1. In Autodiscover at FrontEnd, select tab URL Rewrite, and then Request Blocking. 2. Add string ".*autodiscover\.json.*\@.*Powershell.*" to the URL Path. 3. Condition input: Choose {REQUEST_URI} "We recommend all organizations/enterprises around the world that are using Microsoft Exchange Server to check, review, and apply the above temporary remedy as soon as possible to avoid potential serious damages," GTSC added. Admins who want to check if their Exchange servers have already been compromised using this exploit can run the following PowerShell command to scan IIS log files for indicators of compromise: Get-ChildItem -Recurse -Path -Filter "*.log" | Select-String -Pattern 'powershell.*autodiscover\.json.*\@.*200' Microsoft and ZDI spokespersons were not immediately available for comment when contacted by BleepingComputer earlier today. This is a developing story. Update 9/29/22 7:02 PM EST: Added information about Trend Micro's advisory on the two zero-days. Update 9/30/22 09:50 AM EST: Added the confirmation by Microsoft. Related Articles: Microsoft confirms new Exchange zero-days are used in attacks Sophos warns of new firewall RCE bug exploited in attacks Zero-day in WPGateway Wordpress plugin actively exploited in attacks Trend Micro warns of actively exploited Apex One RCE vulnerability Apple backports fix for actively exploited iOS zero-day to older iPhones * Actively Exploited * Exploit * Microsoft Exchange * Warning * Zero-Day * * * * * Sergiu Gatlan Sergiu Gatlan is a reporter who covered cybersecurity, technology, Apple, Google, and a few other topics at Softpedia for more than a decade. Email or Twitter DMs for tips. * Previous Article * Next Article Comments * shay432 Photo shay432 - 1 day ago + + you forgot the ' at the end of the powershell command Get-ChildItem -Recurse -Path -Filter "*.log" | Select-String -Pattern 'powershell.*autodiscover\.json.*\@.*200' * serghei Photo serghei - 1 day ago + + GTSC did, but you're right. Fixed, thanks! * NoneRain Photo NoneRain - 1 day ago + + "It should be noted that authenticated access to the vulnerable Exchange Server is necessary to successfully exploit either of the two vulnerabilities." - msrc-blog So it needs non-admin credentials for any email user... On premise should block RCE and ports HTTP: 5985 HTTPS: 5986. * Rogues Photo Rogues - 1 day ago + + Probably a stupid question but the fix doesn't mention it - does IIS have to be restarted after adding that IIS server rule? Post a Comment Community Rules You need to login in order to post a comment [Login] Not a member yet? Register Now You may also like: [INS::INS] Popular Stories * keypad Fired admin cripples former employer's network using old credentials * Micosoft Exchange Microsoft confirms new Exchange zero-days are used in attacks Newsletter Sign Up To receive periodic updates and news from BleepingComputer, please use the form below. [ ] [Submit] Latest Downloads * Windows Repair (All In One) Logo Windows Repair (All In One) Version: 4.13.1 2M+ Downloads * Malwarebytes Anti-Malware Logo Malwarebytes Anti-Malware Version: 4.5.12 4M+ Downloads * Everything Desktop Search Logo Everything Desktop Search Version: 1.4.1.1017 21,357 Downloads * Zemana AntiLogger Free Logo Zemana AntiLogger Free Version: 1.8.2.320 51,403 Downloads * Zemana AntiMalware Logo Zemana AntiMalware Version: NA 302,901 Downloads Newsletter Sign Up [ ] [Submit] * Follow us: * * * * Main Sections * News * Downloads * Virus Removal Guides * Tutorials * Startup Database * Uninstall Database * Glossary Community * Forums * Forum Rules * Chat Useful Resources * Welcome Guide * Sitemap Company * About BleepingComputer * Contact Us * Send us a Tip! * Advertising * Write for BleepingComputer * Social & Feeds * Changelog Terms of Use - Privacy Policy - Ethics Statement Copyright @ 2003 - 2022 Bleeping Computer^(r) LLC - All Rights Reserved Login Username [ ] Password [ ] [*] Remember Me [ ] Sign in anonymously [Login] Sign in with Twitter button Sign in with Twitter --------------------------------------------------------------------- Not a member yet? Register Now Reporter Help us understand the problem. What is going on with this comment? * ( )Spam * ( )Abusive or Harmful * ( )Inappropriate content * ( )Strong language * ( )Other [ ] * [ ] Read our posting guidelinese to learn what content is prohibited. Submitting... SUBMIT