A Systematic Review of 2021 Microsoft Exchange Data Breach Exploiting Multiple Vulnerabilities


연구 분야: Strategies



학회: 2022 7th International Conference on Smart and Sustainable Technologies (SpliTech)


초록

At the beginning of 2021 a massive amount of servers using Microsoft's Exchange program were breached by a foreign hacker group called HAFNIUM. This group discovered and exploited 4 different zero-day vulnerabilities which sent the entire cybersecurity community into a panic. Immediately after data breach was discovered, Microsoft and other governmental security agencies alerted all the users. Microsoft released multiple patches to safeguard the attack surface. This paper provides an in-depth analysis of the attack methodology, impacts and possible defense solutions. An estimated 400,000 Exchange Servers were affected by this attack, and a large portion of servers are still vulnerable today. Microsoft has released an effective security patch to stop the exploitation of the vulnerabilities.


Author Profile
Alexis M Pitney

Department of Computer Science and Software Engineering Miami University Oxford Ohio USA

Andorra
Author Profile
Spencer Penrod

Department of Computer Science and Software Engineering Miami University Oxford Ohio USA

Andorra
Author Profile
Molly Foraker

Department of Computer Science and Software Engineering Miami University Oxford Ohio USA

Andorra

📄 논문 정보

발행 연도 2022년
인용수 13
출판 국가 Andorra
사이트 IEEE
좋아요 수 0

연관 논문 목록 (178건)