
針對近期微軟公布修補遭駭客攻擊的Exchange Server漏洞問題,台灣DEVCORE表示早在1月5日便已發現安全漏洞後,並且向微軟通報此項編號命名為「CVE-2021-26855 」,以及「CVE-2021-27065」的零日漏洞,同時也將此項漏洞稱為「ProxyLogon」。 此次揭露的「ProxyLogon」漏洞,是以無需驗證即可使用的遠端程式碼執行 (Pre-Auth Remote Code Execution;Pre-Auth RCE)零日漏洞(Zero-day exploit),可讓攻擊者得以繞過身份驗證步驟,驅使系統管理員協助執行惡意文件或執行指令,進而觸發更廣泛的攻擊。 「ProxyLogon」是微軟近期被揭露最重大的RCE漏洞之一,DEVCORE團隊遵循責任揭露 (Responsible Disclosure)原則,在發現後便第一時間立即於今年1月5日通報微軟進行修補,避免該漏洞遭有心人士利用,造成全球用戶重大損失。而微軟遂於3月2日針對相關漏洞釋出安全更新,避免用戶機敏資訊遭受惡意攻擊。個人想法:遭駭客攻擊的Exchange Server漏洞問題,台灣DEVCORE表示早在1月5日便已發現,並且向微軟通報此項編號命名為「CVE-2021-26855 」,以及「CVE-2021-27065」的零日漏洞,同時也將此項漏洞稱為「ProxyLogon」。 此次揭露的「ProxyLogon」漏洞,是以無需驗證即可使用的遠端程式碼執行 (Pre-Auth Remote Code Execution;Pre-Auth RCE)零日漏洞(Zero-day exploit),可讓攻擊者得以繞過身份驗證步驟,驅使系統管理員協助執行惡意文件或執行指令,進而觸發更廣泛的攻擊。 「ProxyLogon」是微軟近期被揭露最重大的RCE漏洞之一,DEVCORE團隊遵循責任揭露 (Responsible Disclosure)原則,在發現後便第一時間立即於今年1月5日通報微軟進行修補,避免該漏洞遭有心人士利用,造成全球用戶重大損失。而微軟遂於3月2日針對相關漏洞釋出安全更新,避免用戶機敏資訊遭受惡意攻擊。個人想法:微軟是大眾常用的軟體之一,駭客只要察覺漏洞就會進行惡意的攻擊,微軟公布4個Exchange Server的安全漏洞後,就遭受駭客的惡意攻擊,這件事的發生,微軟需更加小心並提高資安的防護。
Regarding the recently disclosed Exchange Server vulnerabilities that were patched by Microsoft after hacker attacks, Taiwan's DEVCORE stated that they had discovered the security vulnerabilities as early as January 5 and reported them to Microsoft. These zero-day vulnerabilities are designated as "CVE-2021-26855" and "CVE-2021-27065", collectively referred to as "ProxyLogon". The disclosed "ProxyLogon" vulnerabilities are pre-authentication remote code execution (Pre-Auth RCE) zero-day exploits that require no authentication, allowing attackers to bypass authentication steps and trick system administrators into executing malicious files or commands, thereby triggering broader attacks. "ProxyLogon" is one of the most significant RCE vulnerabilities recently disclosed by Microsoft. The DEVCORE team followed the principle of responsible disclosure and reported the vulnerabilities to Microsoft on January 5 this year immediately after discovery, ensuring timely patches to prevent malicious exploitation that could cause significant damage to global users. Microsoft subsequently released security updates on March 2 to address the related vulnerabilities, protecting users' sensitive information from malicious attacks.
Personal thoughts: The Exchange Server vulnerabilities exploited by hackers were discovered by Taiwan's DEVCORE as early as January 5, and they reported them to Microsoft. These zero-day vulnerabilities are designated as "CVE-2021-26855" and "CVE-2021-27065", collectively referred to as "ProxyLogon". The disclosed "ProxyLogon" vulnerabilities are pre-authentication remote code execution (Pre-Auth RCE) zero-day exploits that require no authentication, allowing attackers to bypass authentication steps and trick system administrators into executing malicious files or commands, thereby triggering broader attacks. "ProxyLogon" is one of the most significant RCE vulnerabilities recently disclosed by Microsoft. The DEVCORE team followed the principle of responsible disclosure and reported the vulnerabilities to Microsoft on January 5 this year immediately after discovery, ensuring timely patches to prevent malicious exploitation that could cause significant damage to global users. Microsoft subsequently released security updates on March 2 to address the related vulnerabilities, protecting users' sensitive information from malicious attacks.
Personal thoughts: Microsoft is one of the most commonly used software platforms. Once hackers detect vulnerabilities, they will launch malicious attacks. After Microsoft announced four security vulnerabilities in Exchange Server, it suffered from malicious hacker attacks. This incident highlights the need for Microsoft to be more cautious and enhance its cybersecurity protection.