Ars Technica reports that Kremlin-linked hackers are actively exploiting a maximum-severity vulnerability in unpatched Microsoft Exchange servers, gaining persistent access that survives standard remediation measures.
Live updates
Loading updates…
Key facts
- A maximum-severity flaw in Microsoft Exchange servers is under active exploitation.
- Ars Technica attributes the attacks to Kremlin-linked hackers.
- Exploits can grant persistent server access to unpatched networks.
- The access reportedly survives credential rotation and disk re-imaging.
A maximum-severity vulnerability in Microsoft Exchange servers is being actively exploited by Kremlin-linked hackers to backdoor unpatched networks, according to a report published by Ars Technica.
The outlet reports that the exploits can give attackers persistent access to affected servers. That access is described as durable enough to survive common remediation steps that organizations typically rely on to eject intruders.
According to Ars Technica, the persistent server access can withstand both credential rotation and disk re-imaging. Those measures are among the standard defensive responses network administrators use after a suspected compromise, meaning affected organizations may not be able to easily remove the attackers.
The report identifies the flaw as being of maximum severity, the highest rating used to classify security vulnerabilities, and states that it is being exploited in networks that have not yet applied available fixes.
Ars Technica attributes the exploitation activity to Kremlin hackers, indicating a state-linked threat targeting Exchange servers that remain unpatched.
Why it matters
Microsoft Exchange servers handle email and related communications for large numbers of organizations, making them a high-value target. Because the reported access survives standard cleanup measures like credential changes and disk re-imaging, affected organizations could face prolonged compromises that are difficult to fully remediate.
Frequently asked questions
What is the vulnerability being exploited?
Ars Technica describes it as a maximum-severity flaw in Microsoft Exchange servers that is under active exploitation on unpatched networks.
Why is the attack hard to remove?
According to Ars Technica, the exploits can give persistent server access that survives credential rotation and disk re-imaging, two standard remediation steps.
Who is reportedly behind the attacks?
Ars Technica attributes the exploitation to Kremlin-linked hackers.
Timeline
- Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Ars Technica: Exploits can give persistent server access that survives credential rotation and disk re-imaging.
