Thursday, April 17, 2025
HomeComputer SecurityCritical Microsoft Exchange Server Vulnerabilities Could Allow Hackers to Control of Enterprise...

Critical Microsoft Exchange Server Vulnerabilities Could Allow Hackers to Control of Enterprise Networks

Published on

SIEM as a Service

Follow Us on Google News

In a daily routine check-up, the cybersecurity experts of the U.S. National Security Agency have detected two critical Microsoft Exchange Server vulnerabilities.

After detecting the vulnerabilities, the analysts asserted that these two vulnerabilities could enable the threat actors to persistently access and control business networks.

However, in a threat report, the cybersecurity researchers have affirmed on Tuesday, that they have performed the monthly cycle, during the month when Microsoft delivers some patches for the vulnerabilities.

- Advertisement - Google News

The security researchers have found these vulnerabilities proactively, or we can say that the vulnerabilities were disclosed to the security experts. 

Inventory Your Exchange Servers and Update to the latest Cumulative Update

According to the cybersecurity analysts’ recommendation, one should always use the Exchange Server Health Checker script, and users can easily download it from GitHub.  

Once the users run this script, it will eventually notify them if any of your Exchange Servers are performing these updates or not. 

Moreover, users must update to the latest cumulative update immediately so that they can evade themselves from such vulnerabilities.

Microsoft Released Security Updates 

Microsoft stated that these kinds of vulnerabilities are not new, and they have detected the very first vulnerability in April 2021.

Soon after the detection, the team of analysts has reported the vulnerability to Microsoft. And after the report, Microsoft has researched the whole matter and eventually pronounced that they were not aware of such exploits.

However, after knowing all the details regarding the vulnerability, Microsoft has suggested the users to install the latest update so that they can stay protected from such flaws.

Microsoft releases the security updates to patch the security flaws (CVE-2021-28480, CVE-2021-28481, CVE-2021-28482, CVE-2021-28483) found in the following Exchange Servers:-

  • Exchange Server 2013
  • Exchange Server 2016
  • Exchange Server 2019

Not only this, as these two vulnerabilities were also detected by NSA, and they have rated the vulnerability 9.8 out of 10.

According to them, these vulnerabilities are quite critical and harmful for the users. That’s why every customer must use Exchange Online rather than on-premise Exchange Servers.

While on the other side, ESET researchers have declared that nearly 10 different hacking groups were involved in this threat attack, and they are continuously taking advantage of the zero-day vulnerabilities.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity, and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Managing Burnout in the SOC – What CISOs Can Do

The Security Operations Center (SOC) is the nerve center of modern cybersecurity, responsible for...

The Future of Cybersecurity Talent – Trends and Opportunities

The cybersecurity landscape is transforming rapidly, driven by evolving threats, technological advancements, and a...

Mobile Security – Emerging Risks in the BYOD Era

The rise of Bring Your Own Device (BYOD) policies has revolutionized workplace flexibility, enabling...

Model Context Protocol Flaw Allows Attackers to Compromise Victim Systems

A critical vulnerability in the widely adopted Model Context Protocol (MCP), an open standard...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

The Future of Cybersecurity Talent – Trends and Opportunities

The cybersecurity landscape is transforming rapidly, driven by evolving threats, technological advancements, and a...

Mobile Security – Emerging Risks in the BYOD Era

The rise of Bring Your Own Device (BYOD) policies has revolutionized workplace flexibility, enabling...

China Plans Expanded Cybersecurity Cooperation with Russia

China has announced a significant step forward in its partnership with Russia, with plans...