By Interestana AI Editorial — AI-drafted, human-overseen. How we report
22,000 Microsoft Exchange Servers Unpatched Against Critical Vulnerability
Approximately 22,000 Microsoft Exchange servers accessible via the internet are currently unpatched against a critical authentication bypass vulnerability, according to a report by security researchers. This flaw, identified as CVE-2024-21474, carries a CVSS score of 9.8 out of 10, classifying it as 'Critical'. The vulnerability allows unauthenticated attackers to bypass security measures and gain unauthorized access to all user mailboxes hosted on the affected servers. This means that an attacker could potentially read, modify, or delete emails, as well as impersonate users within the organization.
The vulnerability specifically targets the NTLM authentication protocol used by Microsoft Exchange. Attackers can exploit this by tricking a user into connecting to a malicious server, which then allows the attacker to relay the user's NTLM credentials to the vulnerable Exchange server. Once authenticated, the attacker gains full access to the user's mailbox. The ease of exploitation and the severity of the potential impact make this a significant threat to organizations relying on Microsoft Exchange for their email infrastructure.
Microsoft released security updates to address this vulnerability in February 2024. However, the continued presence of nearly 22,000 unpatched servers indicates a widespread failure among organizations to apply these critical patches in a timely manner. This could be due to various reasons, including resource constraints, complex IT environments, or a lack of awareness regarding the severity of the threat. The researchers who identified the vulnerability have not publicly disclosed the exact methods used for scanning and identifying these exposed servers, but the scale of the exposure suggests a broad and systematic approach.
Organizations using Microsoft Exchange are strongly advised to immediately verify if their servers are patched against CVE-2024-21474 and to apply the necessary security updates provided by Microsoft. Failure to do so leaves them highly susceptible to targeted attacks that could lead to significant data breaches and operational disruptions. The ongoing exposure of these servers highlights the persistent challenge of patch management in enterprise environments and the critical need for proactive security practices to protect sensitive data and maintain system integrity.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.