On March 2nd, Microsoft released emergency out-of-band security updates that address four zero-day issues collectively tracked as ProxyLogon (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) in all supported Microsoft Exchange versions that are actively exploited in the wild.
At the time of the release of the security patches, experts estimated that a total of 400,000 Internet-connected Microsoft Exchange servers were affected by the ProxyLogon vulnerabilities. A week later, more than 100,000 installs were still unpatched, while on March 14th, the number of unpatched servers was around 82,000.
“To illustrate the scope of this attack and show the progress made in updating systems, we’ve been working with RiskIQ. Based on telemetry from RiskIQ, we saw a total universe of nearly 400,000 Exchange servers on March 1. By March 9 there were a bit more than 100,000 servers still vulnerable.” reads the post published by Microsoft. “That number has been dropping steadily, with only about 82,000 left to be updated. We released one additional set of updates on March 11, and with this, we have released updates covering more than 95% of all versions exposed on the Internet.”
According to data collected by RiskIQ, the number of unpatched systems is less than 30,000, Microsoft also announced that 92% of worldwide Exchange IPs are now patched or mitigated.
Over the last weeks, Microsoft released other security updates, including ProxyLogon patches for unsupported Microsoft Exchange versions and On-premises Mitigation Tool (EOMT) tool to fix ProxyLogon issues.
The IT giant also updated Microsoft Defender Antivirus to protect unpatched Exchange servers from ProxyLogon attacks.
If you want to receive the weekly Security Affairs Newsletter for free subscribe here.
(SecurityAffairs – hacking, ProxyLogon)
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.