Organizations around the globe continue to address the fallout from the Microsoft Exchange Server zero-day attacks. It was recently announced that hackers may now be exploiting the vulnerabilities in Exchange to drop ransomware into vulnerable systems via backdoor attacks (or Web shells). There is significant urgency for organizations to update their systems and patch immediately to stop these backdoor attacks that originated with Exchange.
Bitsight’s latest global analysis shows that thousands of organizations have been successfully exploited as a result of Microsoft Exchange Server vulnerabilities. Encouragingly, the number of vulnerable systems continues to drop at a healthy rate since our original observations from last week, suggesting that organizations are steadily patching systems. However, thousands of vulnerable systems remain unpatched around the globe, placing those organizations at risk of a damaging ransomware attack or additional exploitation. In addition, there remain thousands of servers that remain exploited with backdoor attacks despite being patched.
Bitsight’s latest observations from March 15-16, 2021 include:
- 316,401 Microsoft Exchange Servers observed
- 64,931 Exchange Servers observed to be vulnerable
- 14,112 unique Exchange Servers detected with backdoors (Web shells)
- 26,085 total Web shells observed on Exchange Servers, confirming that some Exchange Servers have multiple Web shells installed
- 5,537 Exchange Servers with observable, backdoor attack driven vulnerabilities, that have also been patched, implying that those administrators have yet to perform forensics or remediation of their systems
Bitsight finds that:
- 20% of exposed Exchange Servers remain vulnerable. The rate of observable patched Exchange servers is improving. Nearly 65,000 out of 316,000 (20%) observed Exchange servers remain vulnerable as of March 15. This is down from 99,000 (30%) observed vulnerable servers on March 9.
- 4% of exposed Exchange Servers are currently observed with backdoor attack points. There remain a significant number of currently exploited Exchange servers. More than 14,000 (4%) observed Exchange servers are currently exploited. This is down from more than 31,000 (9%) on March 11.
- Nearly 1 in 2 exposed Exchange Servers that contain a backdoor have also been patched. More than 5,500 observed patched systems still have a backdoor attack point, implying that those administrators have yet to perform incident response of their systems.
- The rate of patching Exchange Servers varies by sector. The Government (4.5%) and Utilities (4%) sectors still have the highest rate of vulnerable Exchange servers, though this has improved since March 10. Other sectors show slight improvements in patching vulnerable systems.