• Services
    • Assess
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Press Release
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Alert – Mass Scanning Detected Targeting Unpatched Microsoft Exchange servers
November 24, 2021
Rewterz Threat Alert – XLoader Malware – Active IOCs
November 24, 2021

Rewterz Threat Update – Proof of Concept of CVE-2021-41379 and CVE-2021-42321 Released

November 24, 2021

Severity

High

Analysis Summary

A security researcher has recently released the PoC (proof-of-concept) of CVE-2021-42321, Exchange Post-Authentication RCE affecting Microsoft Exchange servers. 

Threat actors are targeting unpatched environments and Microsoft is urging Exchange admins to patch the bug exploited in the wild.

“We are aware of limited targeted attacks in the wild using one of vulnerabilities (CVE-2021-42321), which is a post-authentication vulnerability in Exchange 2016 and 2019. Our recommendation is to install these updates immediately to protect your environment.” read the announcement published by Microsoft. “These vulnerabilities affect on-premises Microsoft Exchange Server, including servers used by customers in Exchange Hybrid mode. Exchange Online customers are already protected and do not need to take any action.”

On the other hand, a new PoC for Zero-Day vulnerability has been published by security researcher Abdelhamid Naceri. 

“This variant was discovered during the analysis of CVE-2021-41379 patch. the bug was not fixed correctly, however, instead of dropping the bypass,” explains Naceri in his writeup “InstallerFileTakeOver.”

He released the PoC because of frustration with Microsoft’s new bug bounty program. The PoC is being utilized by hackers and threat actors to gain system privileges to vulnerable systems. 

Impact

  • Remote Code Execution
  • Privilege Escalation

Affected Vendors

Microsoft

Affected Products

  • All supported versions of Windows 10 11 and Windows Server 2022

Remediation

It is advised to keep the Exchange Servers up-to date with the latest security patches.

Updates for CVE-2021-42321 can be found below.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42321

Furthermore, users are advised to patch the previously exploited CVE-2021-41379 vulnerability from Microsoft updates.

https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2021-41379
  • Services
    • Assess
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.