13/01/2022

Critical HTTP and Microsoft Exchange Server vulnerabilities – Remote Code Execution

Summary:

On January 11, 2022, Microsoft released patches for critical and important remote code execution (RCE) vulnerabilities that could be appealing to threat actors. There are no reports of active exploitation as of this publication, but Microsoft labeled them as “exploitation more likely.”

HTTP protocol stack vulnerability CVE-2022-21907 impacts multiple Windows versions. The vulnerability affects http.sys, which is a Windows web server implementation that runs in kernel mode. Microsoft describes the vulnerability as “wormable,” meaning that it could be remotely exploited and enable malicious code to spread from one host to another without user interaction.

CVE-2022-21846, CVE-2022-21855, and CVE-2022-21969 could allow threat actors to take control of Exchange servers. These vulnerabilities impact Exchange Server 2013, 2016, and 2019. Threat actors must have an existing foothold in an environment to exploit these vulnerabilities.

Recommendation(s):

Customers should review the Microsoft guidance listed in the References section and apply patches and mitigations as appropriate in their environments.

Questions:

If you have any questions or concerns about this advisory, please contact us via our support desk – support@empsn.org.uk

References:

Keeping Up To Date With Us Is Easy, Sign Up To Our Newsletter Today!

Stay in touch with emPSN, so that you get the latest e-safety advice and invites to our community events.

    Our partners