Rewterz
Rewterz Threat Advisory –CVE-2021-20090 – Router Vulnerability Being Exploited In The Wild
August 9, 2021
Rewterz
Rewterz Threat Advisory – ICS: Delta Industrial Automation Security Zero-Day Vulnerabilities
August 9, 2021

Rewterz Threat Advisory –Multiple Microsoft Exchange Servers Security Vulnerabilities

Severity

High

Analysis Summary

CVE-2021-34473,CVE-2021-34523,CVE-2021-31207

Threat actors started actively scanning for the Microsoft Exchange ProxyShell remote code execution flaws. ProxyShell is the name of three vulnerabilities that could be chained by an unauthenticated remote attacker to gain code execution on Microsoft Exchange servers.

The vulnerabilities are exploited remotely through Microsoft Exchange’s Client Access Service (CAS) running on port 443 in IIS.

Impact

  • Code Execution
  • Unauthorized Access

Affected Vendors

Microsoft

Affected Products

  • Microsoft Exchange Server

Remediation

Microsoft has issued an update to correct this vulnerability. More details can be found at:

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-31207
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34473
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34523