Hackers Exploiting Bug in Microsoft Email Servers

Volexity has observed multiple APT actors exploiting or attempting to exploit on-premise Exchange servers.

Advertisement
By Indo-Asian News Service | Updated: 9 March 2020 17:37 IST
Highlights
  • Hacking groups are exploiting a vulnerability in Microsoft Exchange
  • Microsoft patched the vulnerability in February
  • The vulnerability was discovered by an anonymous security researcher

Volexity has observed multiple APT actors exploiting on-premise Exchange servers

Several state-sponsored hacking groups are exploiting a vulnerability in Microsoft Exchange email servers that the tech giant patched in February, a cyber-security firm has revealed. London-based Volexity saw this vulnerability -- CVE-2020-0688 -- exploited in the wild by advanced persistent threat (APT) actors. The vulnerability was discovered by an anonymous security researcher and reported to Microsoft by way of Trend Micro's Zero Day Initiative.

"Two weeks after the security updates were released, the Zero Day Initiative published a blog post providing more details on the vulnerability. The post made it clear that an attacker could exploit a vulnerable Exchange server if the three criteria are not met," said the Volexity Threat Research team.

Advertisement

"The Exchange Server had not been patched since February 11, 2020; The Exchange Control Panel (ECP) interface was accessible to the attacker and the attacker has a working credential that allows them to access the Exchange Control Panel in order to collect the ViewState Key," the security researchers noted.

Volexity has observed multiple APT actors exploiting or attempting to exploit on-premise Exchange servers.

Advertisement

In some cases, the attackers appear to have been waiting for an opportunity to strike with credentials that had otherwise been of no use.

Many organisations employ two-factor authentication (2FA) to protect their VPN, e-mail, etc., limiting what an attacker can do with a compromised password.

Advertisement

"This vulnerability gives attackers the ability to gain access to a significant asset within an organization with a simple user credential or old service account," said security researchers.

This issue further underscores why changing passwords periodically is a good best practice, regardless of security measures like 2FA.

Advertisement

Microsoft was yet to react to the Volexity report.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Microsoft Exchange
Advertisement

Related Stories

Popular Mobile Brands
  1. Lumio Launches 55-Inch Variants of Vision 9 (2026), Vision 7 (2026) in India
  2. WhatsApp's Might Soon Flag Fraudulent Chats Before You Reply to Scammers
  3. Samsung Galaxy Z Fold 8 Ultra Tipped to Get Battery, Charging Upgrades
  4. Anthropic Brings Its Cybersecurity AI Model Claude Mythos to India
  5.  Xiaomi 18, 18 Pro and 18 Pro Max Specifications Leaked Ahead of Debut
  6. Motorola Edge 2026 With 6.3-Inch Display Goes Official
  1. UK's FCA Warns Premier League Clubs Over Unauthorised Crypto Sponsor Risks
  2. Vivo X500 Pro Max Display and Battery Details Surface Online in Early Leak; Largest Model Said to Feature 6.85-Inch Screen
  3. Google Introduces Fake Call Detection for Android Phones to Curb Call Spoofing Attacks
  4. Google Rolls Out Gemini Thinking Levels Across Platforms With 'Extended' Thinking Mode for All Users
  5. Samsung Galaxy A27 Reportedly Bags US FCC Certification Ahead of Anticipated Launch
  6. NYDFS, European Banking Authority Join Forces to Oversee, Monitor Stablecoin Activities
  7. Meta Reportedly Testing ‘Series’ Feature to Organise Instagram, Facebook Reels Into Episodic Collections
  8. Xiaomi 18 Tipped to Sport 6.4-Inch Display; Pro Models Said to Feature Dual 200-Megapixel Rear Cameras
  9. Realme P4R 5G India Launch Date Revealed Along With Design and Key Specifications
  10. Marvel's Wolverine Gets Visceral Gameplay Trailer at State of Play, Pre-Orders Now Live
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.