Microsoft urges Exchange admins to patch their on-prem servers now

Email virus and scam theme with aerial view of Manhattan, NY
(Image credit: Shutterstock/TierneyMJ)

Microsoft has issued an urgent security update to patch a high severity vulnerability that affects multiple editions of their popular hosted email server Microsoft Exchange, and could be exploited to remotely execute code on vulnerable servers.

According to Microsoft, the security flaw, tracked as CVE-2021-42321, is caused by improper validation of cmdlet arguments.

“We are aware of limited targeted attacks in the wild using one of [the] vulnerabilities (CVE-2021-42321), which is a post-authentication vulnerability in Exchange 2016 and 2019. Our recommendation is to install these updates immediately to protect your environment,” shares Microsoft.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

It goes on to add that the bug only impacts on-premise Microsoft Exchange servers, including those used by customers in Exchange Hybrid mode. Users of the Exchange Online service are already protected against exploitation attempts, and can safely ignore the advisory.

Patch immediately

Reporting on the development, BleepingComputer notes that Microsoft Exchange has been at the receiving end of two major campaigns, which have targeted different, but related vulnerabilities known as ProxyLogon and ProxyShell.

ProxyLogon was first exploited by state-sponsored threat actors back in March to deploy cryptominers, ransomware, and other malware. Then in August, attackers once again were quick to capitalize after security researchers managed to demonstrate a working exploit that consisted of three chained vulnerabilities in Exchange collectively referred to as ProxyShell.

Both issues have since been addressed, but the new vulnerability has once again given threat actors an opportunity to remotely attack unpatched servers, which would explain the urgency in Microsoft’s appeal to get admins to update their vulnerable installations without delay.

Shield your network against malicious traffic with the help of these best firewall apps and services 

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Flag of the People&#039;s Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
Outlook
Dangerous Microsoft Outlook flaw could let hackers send out malware via email
The best free firewall
Microsoft fixes Power Pages security flaw, tells users to be on their guard
A hacker wearing a hoodie sitting at a computer, his face hidden.
Microsoft patches three worrying security flaws in its latest critical update, so update now
Best free Linux firewalls
SonicWall tells admins to patch worrying SSLVPN flaw immediately
Representational image of a cybercriminal
Microsoft just patched a host of worrying security issues, so update now
Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That&#039;s Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand