Microsoft New Exchange Server Zero Days Already Used In Attacks Expect More To Come
The two new zero-day vulnerabilities in Microsoft Exchange Server – CVE-2022-41040 and CVE-2022-41082 – were detailed last week, with warnings that they could allow hackers to remotely gain access to internal services and execute remote code on networks. Now Microsoft has provided more information on how the vulnerabilities have already been used – in attacks that first started in August. In what’s described as a “small number of targeted attacks”, the CVE-2022-41040 and CVE-2022-41082 vulnerabilities were chained together to provide attackers with “hands-on-keyboard access”, which was used to perform Active Directory reconnaissance and to steal data....