These 17,000 unpatched Microsoft Exchange servers are a ticking time bomb
- Reference: 1711611906
- News link: https://www.theregister.co.uk/2024/03/28/germany_microsoft_exchange_patch/
- Source link:
The government regulator says there are 17,000 or more Exchange Server instances in Germany vulnerable to at least one critical vulnerability, out of around 45,000 public-facing servers in the Euro nation running the software.
Of these servers, 12 percent are running a version of Exchange Server that is ordinarily no longer supported, such as Exchange 2010 and 2013, and around a quarter are running Exchange 2016 and 2019 but without vital patches - meaning at least 37 percent are classed as "vulnerable."
[1]
"The fact that there are tens of thousands of vulnerable installations of such relevant software in Germany must not happen," [2]warned Claudia Plattner, president of the BSI.
[3]
[4]
"Companies, organizations and authorities unnecessarily endanger their IT systems and thus their added value, their services or their own and third-party data, which may be highly sensitive. Cybersecurity must finally be high on the agenda. There is an urgent need for action!"
The BIS is trying to get its citizens to patch early. Just last week Google-owned Mandiant [5]warned that German politicians were under active attack from the Russian Cozy Bear crew, who operate under state sanction from Putin's regime.
[6]Crims found and exploited these two Microsoft bugs before Redmond fixed 'em
[7]Microsoft takes another run at closing Exchange brute-force security hole
[8]Microsoft pins hopes on AI once again – this time to patch up Swiss cheese security
[9]From chaos to cadence: Celebrating two decades of Microsoft's Patch Tuesday
Of particular concern is fixing CVE-2024-21410, an elevation-of-privilege vulnerability that Microsoft [10]patched last month . According to German investigators, it's not clear whether as much as 48 percent or so of the country's Exchange servers have fixed up this hole yet, and Microsoft [11]did warn it's a trickier-than-normal update to apply.
We're told BIS is now emailing network providers on a daily basis reminding them to shore up any vulnerable system it detects. It warns that criminals are already on the lookout to exploit these reported flaws and "schools and universities, clinics, doctors' practices, nursing services and other medical facilities, lawyers and tax advisors, local governments and many medium-sized companies are particularly affected."
[12]
"Most of the vulnerabilities are months old and security patches are available," a BIS spokesperson told The Register . "Even if administrators are not responsible fort he quality of the software (Microsoft is), they must now act quickly and consistently." ®
Get our [13]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZgVNxvVtG5@sNJrBDXnb1gAAAEk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2024/240326_Tausende_Exchange-Server_verwundbar.html
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZgVNxvVtG5@sNJrBDXnb1gAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZgVNxvVtG5@sNJrBDXnb1gAAAEk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2024/03/23/russia_cozy_bear_german_politicians_phishing/
[6] https://www.theregister.com/2024/02/14/patch_tuesday_feb_2024/
[7] https://www.theregister.com/2023/10/11/microsoft_exchange_bug_fix/
[8] https://www.theregister.com/2023/11/03/microsoft_secure_future_initiative/
[9] https://www.theregister.com/2023/10/11/microsoft_patch_tuesday_turns_20/
[10] https://www.theregister.com/2024/02/14/patch_tuesday_feb_2024/
[11] https://techcommunity.microsoft.com/t5/exchange-team-blog/released-2024-h1-cumulative-update-for-exchange-server/ba-p/4047506
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZgVNxvVtG5@sNJrBDXnb1gAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://whitepapers.theregister.com/
Re: Would You Entrust Mission-Critical Business Systems ...
In my experience, a lot of people setup an Exchange server as they thought it would bolster their IT credibility. But once it was running, they didn't know how to manage it. The instructions and down-time for patching (or worse, upgrades) scare them, so they just leave the server in corner and try to forget about it.
By the time my team come across them, the servers are often in a dire situation and need a serious amount of TLC to stabilise just so we can migrate the user data off.
Re: Would You Entrust Mission-Critical Business Systems ...
Yup, been there, done that.
Other problem is for a lot of the recent SU's it not just been applying the update and rebooting, you've needed to run extra scripts and so on and so forth which makes things extra scary.
If they've even noticed that there is an update available.
Re: Would You Entrust Mission-Critical Business Systems ...
The trouble is t that people are deploying new systems on obsolete unsupported software, it’s that the new shiny software will become obsolete due to the provider.deciding to cease providing updates etc…
Remember part of the problem with Exchange is that Microsoft themselves tripped up on their roadmap and time.y delivery of replacements to Echange server whilst at the same time sticking to their arbitrary EOL dates for their existing products.
17000+
And that's only in Germany.
I shudder to think of how many more might exist around the world.
Re: 17000+
Can't remember the stats but I'm sure the FBI know, for US at least.
Remember they went in to a massive # of servers in the US and removed web shells back in 2021 so they'd obviously been scanning for all the servers with public IP's that they could fine.
Re: 17000+
Just looking at the headline I thought it probably wasn't too bad considering how many instances there must be worldwide. Then realised it was just one country. Wow.
Those damned reboots
If it weren't for the requirement to reboot production servers at almost every update then I am sure that updating would be done far more often..
Linux systems very rarely require actual reboots whereas Windows is the defacto condition.
How many here have gone down on their knees and prayed and made offering to their IT Gods that the server will actually get back into a running state , with all services up after the obligatory reboot.
Thank god for VMs and Snapshots, it has seriously saved our skin on multiple occasions.
And it's not only the OS updates that make you sweat. Some of our Reporting and ETL services make us tremble too.
Re: Those damned reboots
Ah, yes, but remember that Linux still has to restart updated services so they'll be out of action for as long as a fraction of a second.
What sort of IT department doesn't patch their Exchange servers?
That said, Microsoft makes the cumulative update process needlessly complex - it's effectively a manual upgrade install from an ISO. Why can't it just be delivered through the normal update channels? CUs are normally twice a year, and they only support the most recent two.
Would You Entrust Mission-Critical Business Systems ...
... to obsolete, unsupported software?
How much is your job worth?