Microsoft takes another run at closing Exchange brute-force security hole
- Reference: 1697048874
- News link: https://www.theregister.co.uk/2023/10/11/microsoft_exchange_bug_fix/
- Source link:
According to Microsoft, the update is another attempt at fixing [1]CVE-2023-21709 , an elevation-of-privilege vulnerability with a relatively straightforward exploitation method. A brute-force attack could allow an attacker to be authenticated as another user, assuming the password was relatively weak.
The vulnerability was dealt with in August's Patch Tuesday but also required the user to disable the IIS Token Cache module via a script or take manual action. It has taken a while, but as of this latest patch, the root cause has been apparently [2]fully dealt with .
[3]
Microsoft said: "We recommend installing the IIS fix after which you can re-enable Token Cache module on your Exchange servers."
[4]
[5]
The Windows giant reckons customers using Exchange Online remain unaffected by the problems. Assuming, that is, they can make their email work.
Some users were [6]reporting issues with the email service earlier today, with external email sporting a "Server busy" message.
[7]From chaos to cadence: Celebrating two decades of Microsoft's Patch Tuesday
[8]Microsoft gives unexpected tutorial on how to install Linux
[9]Microsoft reportedly runs GitHub's AI Copilot at a loss
[10]It's 2023 and Microsoft WordPad can be exploited to hijack vulnerable systems
One Register reader reported: "I currently have over a thousand mails waiting to go into the 365 infrastructure for our customers, but other larger orgs are reporting tens of thousands of emails stuck in the queue."
The Register asked Microsoft for more details on the matter, and we'll update should we hear anything back. In the meantime, the issue has been assigned EX680695 in the Admin Center.
[11]
Microsoft, in its note on the issue, said the root cause of the outage was: "A recent service update, applied to a section of infrastructure responsible for enforcing IP address anti-spam rules, contains a change which is inadvertently causing impact."
Make of that what you will, and the use of the word "inadvertently."
As for the current status for affected users, Redmond has noted the issue is lurking within its SQL infrastructure behind the scenes and the software titan is having to manually add IP addresses to an allowed list.
[12]
Our reader noted: "Seemingly despite there being a form to fill in which 'whitelists' the sending IPs, this has no effect." The timing of the outage is unfortunate, although Exchange Online is no stranger to problems. Large chunks of Microsoft 365 [13]fell over earlier this year due to issues with Microsoft's caching infrastructure.
Today's problems look isolated to Exchange Online though are a little awkward considering Microsoft's declarations concerning the state of the service.
Maybe the best way to have the most reliable service is to have no service at all. ®
Get our [14]Tech Resources
[1] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21709
[2] https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2023-exchange-server-security-updates/ba-p/3892811
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZScbCWXCU3dcIjFXxRNx3QAAAMA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZScbCWXCU3dcIjFXxRNx3QAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZScbCWXCU3dcIjFXxRNx3QAAAMA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.reddit.com/r/sysadmin/comments/1755npg/anyone_else_seeing_outlook_mail_delivery_problems/?rdt=47131
[7] https://www.theregister.com/2023/10/11/microsoft_patch_tuesday_turns_20/
[8] https://www.theregister.com/2023/10/11/microsoft_documents_installing_linux/
[9] https://www.theregister.com/2023/10/11/github_ai_copilot_microsoft/
[10] https://www.theregister.com/2023/10/10/october_2023_patch_tuesday/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZScbCWXCU3dcIjFXxRNx3QAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZScbCWXCU3dcIjFXxRNx3QAAAMA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://www.theregister.com/2023/04/20/microsoft_365_services_outage/
[14] https://whitepapers.theregister.com/
Re: Hope springs eternal
You need to come up with a catchy name first, some sort of "local cloud" pun.
"Run your own Drizzle server" or something like that.
Re: Hope springs eternal
Hopefully someone will need my Lotus Domino and Notes skills before I completely forget them. R5 was almost usable by end users.
The service health pages in M36x are reporting that the issue has now been resolved.
And on the subject of Patch Tuesday emissions, has anyone else noticed that this month's has delivered some nag icons to Windows Server 2022 - start menu and system tray - to try to get you to enrol the devices in Azure Arc?
So far as I can see it is only the 2022 version (not 2016 and 2019), and the icons only appear if the Windiws instance is running on-prem (bare meta or VM). Doesn't appear in Azure VMs, as would be expected. No idea what happens with those on other cloudy platforms.
Is that in the Security Only updates?
Hope springs eternal
Given that everything old comes back again, I can't wait for all this Online malarky to be folded back into local servers.
Because I dearly hope that CxOs will tire of relying on Borkzilla's ceaselessly failing infrastructure.
Maybe they'll even go for something else entirely. There has to be something else than Exchange in this world, no ?
Please ?