Menu

Call us on 03450 21 21 51

The great Microsoft exchange hack: A penetration tester’s guide
The SRM Blog

The great Microsoft exchange hack: A penetration tester’s guide

Dean Moulden

Written by Dean Moulden

17th March 2021

Share this article

Microsoft Exchange Hack

Senior Penetration Tester, Dean Moulden outlines the details of Microsoft’s high-profile hack and provides his advice on remediation and prevention.

The recent disclosure of several Microsoft Exchange Zero-Day exploits has made big news with reports of more than 60,000 victims having already been affected worldwide. With government agencies thought to be amongst those compromised, it’s no surprise that this attack has hit the headlines.

Accused by many of being slow to share details of the breach, Microsoft has since named state-sponsored hacker group, Hafnium, as the threat actors behind the attack. Believed to be working for the Chinese government, Hafnium is a highly sophisticated collective with the expertise to find and chain together multiple exploits to gain access to valuable information and carry out cyber espionage to spy on governments and associated agencies.

Previous reports suggest that Hafnium has previously targeted defence contractors with connections to the US government and it’s not implausible that they could have done the same with this new exploit chain.

What happened and when?

Forensic analysis of compromised systems has shown that exploitation was occurring in the wild as early as the 6th January 2021. Microsoft did not publicly disclose the associated vulnerabilities until 2nd March 2021 and released a patch for the affected issues shortly after. This means that the attackers likely had months in which to exploit these Zero-Day vulnerabilities and during this time, there is very little that affected parties could have done about it.

The specific attack is made up of small exploits which, when combined, are extremely impactful.

The first of these is a server-side request forgery (SSRF) issue in Exchange that allowed attackers to authenticate as the Exchange server (CVE-2021-26855).

An insecure deserialization issue (CVE-2021-26857) in the Unified Messaging service (which is used to provide voice message functionality in Exchange) allowed Hafnium to run code as SYSTEM on the Exchange server. It has been reported that in order to exploit this, an attacker would require either administrator privileges or would have to gain this via another exploit.

An arbitrary file write vulnerability in exchange (CVE-2021-26858) was found to allow the attacker the ability to write a file to any path on the server provided they were able to authenticate. An attacker could authenticate either with valid admin credentials or by exploiting the previously mentioned SSRF issue. Another arbitrary file write vulnerability was found (CVE-2021-27065), which could be used in the same way.

Reports suggest that Hafnium chained the SSRF issue with an exploit for arbitrary file write issue (CVE-2021-27065) to compromise its victims and were also able to upload web shells via this method to ensure their access to these systems was more permanent. Attackers are also known to have pivoted further into an organization after this breach to establish deeper persistence.

The city of Prague and the Czech Republic’s Labour Ministry have admitted to being affected by this breach. But what about UK government agencies and contractors?

Documents obtained by Sky News suggest there was a record number of security breaches in 2020 originating from the British military’s private sector partners and reportedly include email breaches. More breaches were reported in December than any other month last year – with a jump of 262% on the same period in the previous year. This is also 31% higher than the next most damaging month in 2021.

Although a direct link has not been established and there is no evidence to suggest that this attack was used against British military partners, it is plausible that Zero-Day exploits and state-sponsored hacker groups were behind some of these attacks. It could even be the case that Hafnium used their exploit chain to gain access to systems associated with the British military and associated contractors in December, although again this has not been confirmed. The full Sky News article can be read here.

Once Microsoft released the relevant patches for identified vulnerabilities, unpatched systems were more actively exploited in the wild. This indicates that other malicious parties managed to reverse engineer the patch and create their own exploits. The issues in this article are now actively being exploited by more than 10 hacker groups, some of which are thought to be government-backed cyber-espionage teams.

Remediation and prevention: what now?

The best course of action is to apply security updates as soon as possible and to ensure systems are fully up to date. Patches have been released for the Exchange server issues by Microsoft. However, what can be done in the event that no patch is available?

It is possible to restrict access to the affected service which, in this case, would be to the affected Exchange HTTPS service. A Web Application Firewall (WAF) could also be used to restrict access when suspect behaviour is identified. However, there is less chance of access being blocked when little information is known about the attack in question and associated payloads.

File Integrity Monitoring (FIM) can also be used on the server to help identify and prevent the upload of malicious payloads and web shells.

If you suspect that you may have been a victim of this breach, or would like to know how you can improve your resilience to similar attacks, get in touch with the SRM team today by clicking here.

Find out more about SRM’s penetration testing services.