Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Summary
A critical vulnerability in Microsoft Exchange Server is being actively exploited by a state-sponsored hacking group linked to the Kremlin. The exploits allow for persistent access to compromised servers, even after credentials have been changed or disks have been re-imaged.
IFF Assessment
This vulnerability allows attackers to gain persistent access, posing a significant threat to organizations relying on Exchange Server.
Severity
The vulnerability allows for remote code execution and persistent access, which is highly critical. The CVSS score of 9.8 reflects the severity of these impacts.
Defender Context
This situation highlights the ongoing threat of sophisticated nation-state actors targeting critical infrastructure like email servers. Defenders should prioritize patching Exchange servers immediately and implement robust monitoring for any signs of compromise, particularly focusing on indicators of persistence.