Microsoft Exchange is a critical business software used by organizations around the world for email. Sensitive data and communications are stored and transacted on the platform daily. In an unusual situation, threat actors have performed mass exploitation on zero-day vulnerabilities associated with Microsoft Exchange.
This attack is unusual because it’s one of the rare situations where bad actors had performed mass exploitation on near-zero day threat vectors, particularly those that allowed for RCEs. Many organizations were -- and are -- still vulnerable to exploitation.
Bitsight’s latest global analysis shows that despite repeated warnings from Microsoft and government agencies, many organizations still have not patched vulnerable Microsoft Exchange Servers and remain at risk of threat vector exploitation:
- Nearly 1 in 3 companies who use Microsoft Exchange are currently running vulnerable versions.
- Nearly 1 in 3 exposed Microsoft Exchange servers are currently vulnerable to threat vectors.
- More than 5% of global government entities are currently running vulnerable versions of Exchange.
- More than 340 U.S. government entities at the state, local, and Federal level -- including multiple U.S. Federal agencies -- are currently running vulnerable versions of Microsoft Exchange.
- More than 5% of global utilities are currently running vulnerable versions of Exchange.
- More than 3% of global aerospace/defense companies are currently running vulnerable versions of Exchange.
Despite recent warnings to patch threat vectors in their systems, Bitsight observes a very high rate of confirmed vulnerable versions of Exchange currently running across the globe.
Bitsight is tracking the total number of companies running confirmed vulnerable versions of Microsoft Exchange. Organizations rely on Exchange as a mail and calendar service that stores company emails in a centralized server, giving successful hackers access to contact information and sensitive business communication if a server is infiltrated. On March 10, we assess that nearly 1 in 3 companies with Exchange are currently running vulnerable versions. These organizations should initiate a threat vector incident response process under the assumption that their server was compromised.