Microsoft Exchange RCE/SSRF Vulnerability | Techzone

General News

Summary

We recommend applying patches from Microsoft to fix the root cause as soon as available. Microsoft published a workaround to prevent exploitation of the vulnerability (see [1]). Alternatively, you can configure the following Deny Rule on Airlock Gateway as a virtual patch to prevent exploitation: Pattern type: Path Case-sensitivity: NO (default) Invert: OFF (default) Multiple single line Regex: ON (default) Pattern: Note: The pattern is more "aggressive" than similar patterns communicated by Microsoft [1] due to the newest known evasion techniques. We do not expect false positive blocks. Enable the Deny Rule on the Exchange Autodiscover mappings.

Classifications

industries
No industries detected
applications
Accounting and Taxes

AskAI Classifications

Labels
Software Development SaaS Standard Software

Linked Companies

Ergon Informatik AG
$10M to $25M
Microsoft
$1B+