Skip to main content

Microsoft vulnerabilities exploitation - updated advice

Urgent updates and actions following Exchange server vulnerabilities
Image of an antivirus alert on a desktop computer
iStock.com/Jane_Kelly

This alert is an updated version of the NCSC alert from 3 March 2021 and contains additional information on installing updates and detection.

On 2 March 2021 Microsoft made public that sophisticated actors had attacked a number of Exchange servers. In response to this they released multiple security updates for affected servers. This does not affect Exchange Online.

The updates were released ahead of the monthly update cycle because four of the seven vulnerabilities have been used in ongoing attacks. The security updates fix the vulnerabilities exploited in the attack.

A wide variety of threat actors are using automated tools to scan for Exchange servers where updates are not installed. The actors then install malicious software to servers identified as vulnerable. On 11 March it was reported that ransomware actors have also exploited these vulnerabilities, or made use of the installed malicious software, to install ransomware on a network.