---
title: Active Exploitation of Microsoft Exchange On-Prem Vulnerabilities
description: Microsoft has recently released a group of updates to prevent attacks on the following vulnerabilities for Exchange on-premises.
---

[News | KiZAN Technologies ](https://www.kizan.com/news)

# [Active Exploitation of Microsoft Exchange On-Prem Vulnerabilities](https://www.kizan.com/news/active-exploitation-of-microsoft-exchange-on-prem-vulnerabilities)

 Written by [Mark McIntosh](https://www.kizan.com/news/author/mark-mcintosh) | Mar 3, 2021 3:57:47 PM

# Microsoft has recently released a group of updates to prevent attacks on the following vulnerabilities for Exchange on-premises:

[CVE-2021-26855](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26855) is a server-side request forgery (SSRF) vulnerability in Exchange that allowed the attacker to send arbitrary HTTP requests and authenticate as the Exchange server.

[CVE-2021-26857](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26857) is an insecure deserialization vulnerability in the Unified Messaging service. Insecure deserialization is where untrusted user-controllable data is deserialized by a program. Exploiting this vulnerability gave HAFNIUM the ability to run code as SYSTEM on the Exchange server. This requires administrator permission or another vulnerability to exploit.

[CVE-2021-26858](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26858) is a post-authentication arbitrary file write vulnerability in Exchange. If HAFNIUM could authenticate with the Exchange server then they could use this vulnerability to write a file to any path on the server. They could authenticate by exploiting the CVE-2021-26855 SSRF vulnerability or by compromising a legitimate admin’s credentials.

[CVE-2021-27065](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-27065) is a post-authentication arbitrary file write vulnerability in Exchange. If HAFNIUM could authenticate with the Exchange server then they could use this vulnerability to write a file to any path on the server. They could authenticate by exploiting the CVE-2021-26855 SSRF vulnerability or by compromising a legitimate admin’s credentials.

Ref: [https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/](https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/)

 

The patches that Microsoft has released can only be applied to the following specific versions:

- [Exchange Server 2010 (for Service Pack 3 – this is a Defense in Depth update)](https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2010-service-pack-3-march-2-2021-kb5000978-894f27bf-281e-44f8-b9ba-dad705534459)
- [Exchange Server 2013 (CU 23)](https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2019-2016-and-2013-march-2-2021-kb5000871-9800a6bb-0a21-4ee7-b9da-fa85b3e1d23b)
- [Exchange Server 2016 (CU 19, CU 18)](https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2019-2016-and-2013-march-2-2021-kb5000871-9800a6bb-0a21-4ee7-b9da-fa85b3e1d23b)
- [Exchange Server 2019 (CU 8, CU 7)](https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2019-2016-and-2013-march-2-2021-kb5000871-9800a6bb-0a21-4ee7-b9da-fa85b3e1d23b)

If your server is not on one of these currently supported update versions, you will first need to apply previous updates to your Exchange server to reach the minimum requirement above.

## KiZAN can check your servers for evidence of a breach and apply the necessary patches to secure your Exchange environment.

$1300 per update needed, per server

 

[View full post](https://www.kizan.com/news/active-exploitation-of-microsoft-exchange-on-prem-vulnerabilities)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Mark McIntosh"
  },
  "dateModified" : "2021-06-02T14:02:47.941Z",
  "datePublished" : "2021-03-03T15:57:47Z",
  "headline" : "Active Exploitation of Microsoft Exchange On-Prem Vulnerabilities",
  "image" : {
    "@type" : "ImageObject",
    "height" : 1036,
    "url" : "https://f.hubspotusercontent40.net/hubfs/2059240/Exchange%20Hack_Social.jpg",
    "width" : 2000
  },
  "mainEntityOfPage" : "https://www.kizan.com/news/active-exploitation-of-microsoft-exchange-on-prem-vulnerabilities",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60.0,
      "url" : "https://cdn2.hubspot.net/hubfs/2059240/KiZAN_logoBlueOrgDot120px.png",
      "width" : 124.137924
    },
    "name" : "News"
  }
}
```