Protect your Microsoft Exchange Server today, Hacker are scanning

Microsoft Exchange servers had a vulnerability of CVE-2020-0688 and developers already resolved this issue two weeks before. But hackers are still scanning unpatched Microsoft Exchange Server across the internet to exploit.

The issues is about the Exchange Control Panel component, in creating a unique cryptographic key during installation. Due to this, hackers are searching the unpatched servers, to remotely execute arbitrary code with SYSTEM privileges and compromise the vulnerable servers.

Researchers Kevin Beaumont and Troy Mursch warned that attacker are compromising the unpatched servers and stealing the passwords and other confidential information from the servers.

Twitter and logs of scan

Demonstration of this vulnerability has already been done by Zero Day Initiative.

Click on this link below to watch the demo of the issue.

Demonstrating CVE-2020-0688: A Remote Code Execution Bug in Microsoft Exchange

HOW TO FIX

Request to the System Administrators to install the patches as soon as possible.

Version Security Bulletin Patches
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 30 4536989 Security update
Microsoft Exchange Server 2013 Cumulative Update 23 4536988 Security update
Microsoft Exchange Server 2016 Cumulative Update 14 4536987 Security update
Microsoft Exchange Server 2016 Cumulative Update 15 4536987 Security update
Microsoft Exchange Server 2019 Cumulative Update 3 4536987 Security update
Microsoft Exchange Server 2019 Cumulative Update 4 4536987 Security update