﻿{"id":1072,"date":"2021-03-03T14:49:19","date_gmt":"2021-03-03T20:49:19","guid":{"rendered":"https:\/\/www.uv.mx\/csirt\/?p=1072"},"modified":"2021-03-03T14:49:19","modified_gmt":"2021-03-03T20:49:19","slug":"03-03-21-vulnerabilidad-en-exchange-server","status":"publish","type":"post","link":"https:\/\/www.uv.mx\/csirt\/boletines\/vulnerabilidades\/03-03-21-vulnerabilidad-en-exchange-server\/","title":{"rendered":"03\/03\/21 Vulnerabilidad en Exchange Server"},"content":{"rendered":"<p>&nbsp;<\/p>\n<div style=\"width: 752px;max-width: 752px;height: auto;border: 1px solid #369;margin: 0px auto;background-color: #fff\">\n<p><img decoding=\"async\" style=\"width: 750px\" src=\"https:\/\/www.uv.mx\/csirt\/files\/2021\/02\/boletin-encabezado.jpg\" alt=\"\" \/><\/p>\n<table style=\"width: 100%\" border=\"0\" cellspacing=\"1\" cellpadding=\"1\" align=\"center\">\n<tbody>\n<tr>\n<td><img decoding=\"async\" style=\"width: 144px;height: 25px\" src=\"https:\/\/www.uv.mx\/csirt\/files\/2021\/02\/cintillo_critico.jpg\" alt=\"\" \/><\/td>\n<td style=\"text-align: right\"><span style=\"font-size: 18px\"><span style=\"color: #666666\"><span style=\"font-family: tahoma,geneva,sans-serif\">03 de marzo de 2021<\/span><\/span><\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr \/>\n<div style=\"background-color: #e6e6e6;line-height: 1.4\"><strong>Vulnerabilidad en Exchange Server<\/strong><\/div>\n<div style=\"background-color: #e6e6e6;line-height: 1.4\"><span style=\"font-size: 16px\">ID: 03032107<\/span><\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<hr \/>\n<\/div>\n<div style=\"background-color: #f5f5f5;line-height: 1.4\">\n<p><span style=\"color: #28519b\"><span style=\"font-size: 16px\"><strong>Descripci\u00f3n<\/strong><\/span><\/span><\/p>\n<p style=\"text-align: justify\">Microsoft ha publicado una actualizaci\u00f3n fuera de ciclo (periodo de actualizaciones) a raz\u00f3n de que se han detectado ataques activos, esta actualizaci\u00f3n cubre cuatro vulnerabilidades que tienen los identificadores CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 y CVE-2021-27065, combinados permiten un acceso completo al servidor haciendo uso de 0-day conocidos por lo atacantes que les permite insertar una <em>shell<\/em>\u00a0remota en el servidor y controlarlo.<\/p>\n<p style=\"text-align: justify\">Exchange 2010 recibir\u00e1 esta actualizaci\u00f3n a\u00fan cuando est\u00e1 fuera de soporte. Si cuentas con alguna de estas soluciones te sugerimos aplicar las actualizaciones correspondientes para evitar que un atacante tome el control de un sistema afectado.<\/p>\n<\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<p><span style=\"color: #28519b\"><strong><span style=\"font-size: 16px\">Producto afectado<\/span><\/strong><\/span><\/p>\n<\/div>\n<div style=\"background-color: #c1272d;line-height: 1.4\">\n<p>&nbsp;<\/p>\n<\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<ul>\n<li>Microsoft Exchange Server 2010<\/li>\n<li>Microsoft Exchange Server 2013<\/li>\n<li>Microsoft Exchange Server 2016<\/li>\n<li>Microsoft Exchange Server 2019<\/li>\n<\/ul>\n<hr size=\"2\" \/>\n<\/div>\n<div style=\"background-color: #f5f5f5;line-height: 1.4\">\n<p><span style=\"color: #28519b\"><span style=\"font-size: 16px\"><strong>Soluci\u00f3n:<\/strong><\/span><\/span><\/p>\n<p style=\"text-align: justify\">Se recomienda a los administradores que hagan uso de alguna de las soluciones listadas aplicar las actualizaciones que se encuentran disponibles para su descarga e instalaci\u00f3n.<\/p>\n<p style=\"text-align: justify\">El equipo de seguridad de Microsoft Defender ha puesto a disposici\u00f3n una publicaci\u00f3n llamada <a href=\"http:\/\/boletines.uv.mx\/\/lt.php?tid=fB0ADVZTBFEDW09XCVRSSwYLUlobAQwCVUxRUFAAAwQHB1RbVFBLB1NWAV0PVgJLBARWUBtXCQRdTAVXU1ZMUVcEVAAGUVJQUVtVGAlVW1FXVgQGG1BZUlVMUAcAU0wHBVVXFQQGAgVRAQAHXVBSUA\">Defendiendo servidores Exchange bajo ataque<\/a>\u00a0que permite comprender algunas pr\u00e1cticas sobre la detecci\u00f3n de actividad maliciosa.<\/p>\n<p>Para m\u00e1s informaci\u00f3n:<\/p>\n<p><a href=\"https:\/\/msrc-blog.microsoft.com\/2021\/03\/02\/multiple-security-updates-released-for-exchange-server\/\">https:\/\/msrc-blog.microsoft.com\/2021\/03\/02\/multiple-security-updates-released-for-exchange-server\/<\/a><\/p>\n<\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<hr \/>\n<\/div>\n<p><img decoding=\"async\" style=\"width: 750px;height: 120px\" src=\"https:\/\/www.uv.mx\/csirt\/files\/2021\/02\/cintillo_inferior.jpg\" alt=\"\" \/><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; 03 de marzo de 2021 Vulnerabilidad en Exchange Server ID: 03032107 Descripci\u00f3n Microsoft ha publicado una actualizaci\u00f3n fuera de ciclo (periodo de actualizaciones) a raz\u00f3n de que se han detectado ataques activos, esta actualizaci\u00f3n cubre cuatro vulnerabilidades que tienen los identificadores CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 y CVE-2021-27065, combinados permiten un acceso completo al servidor haciendo [&hellip;]<\/p>\n","protected":false},"author":2037,"featured_media":813,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ventana_nueva":"","tipo_url":"","url":"","extracto":"","imagen_halign":"","imagen_valign":"","bg_size":"","text_hide":"","media_url":"","tipo_media":"","video_url":"","video_pos":"","video_youtube":"","footnotes":""},"categories":[17,15],"tags":[27,33],"class_list":["post-1072","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-criticos","category-vulnerabilidades","tag-boletines","tag-vulnerabilidad"],"_links":{"self":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/posts\/1072","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/users\/2037"}],"replies":[{"embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/comments?post=1072"}],"version-history":[{"count":1,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/posts\/1072\/revisions"}],"predecessor-version":[{"id":1073,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/posts\/1072\/revisions\/1073"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/media\/813"}],"wp:attachment":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/media?parent=1072"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/categories?post=1072"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/tags?post=1072"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}