Microsoft vulnerabilities exploitation - updated advice
Urgent updates and actions following Exchange server vulnerabilities
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

This alert is an updated version of the NCSC alert from 3 March 2021 and contains additional information on installing updates and detection.
On 2 March 2021 Microsoft made public that sophisticated actors had attacked a number of Exchange servers. In response to this they released multiple security updates for affected servers. This does not affect Exchange Online.
The updates were released ahead of the monthly update cycle because four of the seven vulnerabilities have been used in ongoing attacks. The security updates fix the vulnerabilities exploited in the attack.
A wide variety of threat actors are using automated tools to scan for Exchange servers where updates are not installed. The actors then install malicious software to servers identified as vulnerable. On 11 March it was reported that ransomware actors have also exploited these vulnerabilities, or made use of the installed malicious software, to install ransomware on a network.
The vulnerabilities affect Microsoft Exchange Server. The affected versions are:
A defence in depth update for Microsoft Exchange Server 2010 has also been released. Organisations running an out-of-support version of Exchange Server should update to a supported version without delay.
Exchange Online (as part of Microsoft 365) is not affected.
This should be the first priority for all UK organisations using affected versions of Microsoft Exchange Server.
This advice applies irrespective of update status because a compromise may have occurred before updates were installed and installing the update will not remediate a previous compromise.
Further information regarding indicators of compromise and detection can be found below:
If organisations identify activity of concern, they should consider whether to engage with an IR company using standard organisational incident response processes.
Affected UK organisations should report any suspected compromises to the NCSC via the website.


