
好久不见,正月还没过年,向大家拜个晚年!算一算,距离上次推送又快3个月了,想必大家已经习惯了我的忙和懒的停更理由了,但是今天微软又发布了Exchange Server相关的安全补丁了,没办法了,这个事再忙再懒也得给大家提个醒了:
2021年3月3日微软披露了多个Exchange Server相关的高危重大漏洞, 并已发布了相关修复补丁,包含已经停止支持的Exchange Server 2010,我们强烈建议大家立即安装修复!
总结以下几点,让您快速了解相关信息:
1、安全公告列表:
本次披露Exchange Server安全漏洞足足七个,都是远程执行代码相关的,详细情况看下面安全公告:
CVE-2021-26412 Microsoft Exchange Server Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26412
CVE-2021-27078 Microsoft Exchange Server Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-27078
CVE-2021-26854 Microsoft Exchange Server Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26854
CVE-2021-26855 Microsoft Exchange Server Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26855
CVE-2021-27065 Microsoft Exchange Server Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-27065
CVE-2021-26857 Microsoft Exchange Server Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26857
CVE-2021-26858 Microsoft Exchange Server Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26858
2、漏洞影响:
这次的漏洞,CVSS评分最高的是9.1,可以说是非常严重,它不单单从七个之多的数量来评估的,从微软对早已停止支持的Exchange Sever 2010也同时提供修复补丁就可以看出来。而且已经有被利用的案例,有关漏洞利用和检查是否被攻击的信息可以参考以下微软安全团队和 Volexity发布的两个博客文章:
HAFNIUM targeting Exchange Servers with 0-day exploits
https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
Operation Exchange Marauder: Active Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities
https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/
3、针对这次安全漏洞发布的KB列表如下:
Exchange Server 2013及以上版本:
https://support.microsoft.com/help/5000871
Exchange Sever 2010版本:
https://support.microsoft.com/help/5000978
4、补丁下载地址如下:
Security Update For Exchange Server 2019 CU8补丁下载地址:
https://www.microsoft.com/zh-CN/download/details.aspx?id=102770
Security Update For Exchange Server 2019 CU7补丁下载地址:
https://www.microsoft.com/zh-CN/download/details.aspx?id=102771
Security Update For Exchange Server 2016 CU19补丁下载地址:
https://www.microsoft.com/zh-CN/download/details.aspx?id=102772
Security Update For Exchange Server 2016 CU18补丁下载地址:
https://www.microsoft.com/en-us/download/details.aspx?id=102773
Security Update For Exchange Server 2013 CU23补丁下载地址:
https://www.microsoft.com/zh-CN/download/details.aspx?id=102775
Update Rollup 32 For Exchange 2010 SP3补丁下载地址:
https://www.microsoft.com/zh-CN/download/details.aspx?id=102774
5、补丁安装要求
本次补丁虽然因为考虑到严重程度,为已停止中支持的Exchange Server 2010提供了修复补丁。但是Exchange Server 2013以上的版本,还是和之前一样,依然只是根据当前支持的版本来提供的,如Exchange Sever 2013 CU23、Exchange Server 2016或Exchange Server 2019需要是最新和N-1的版本的环境。如果当前Exchange版本还没有升级到这些版本,需要事先升级到支持的版本然后再打补丁。
6、该如何临时规避这个安全风险?
如果因为种种原因,目前无法及时安装补丁,可能需要考虑将Exchange Server的OWA,ECP等基于Web相关服务从公网的发布中移除,或是对访问权限进行限制,但这些限制自然会影响部分外部用户的合作,比如手机访问邮件,可以要配合VPN等访问来方便用户使用。
7、下一个CU将包含本次的修复补丁
根据微软Exchange产品组的CU包发布频率,本月中旬将会发布2021年第一季的Exchange Server更新,产品组已经确认这些安全补丁也会包括在新的CU中,如果延迟到和CU一起安装则不需要分别更新。
最后还是提醒大家,立即安装补丁,如果您有问题,欢迎留言或是到5DMail专属微信群来讨论!

