Are Exchange Tool Machines Vulnerable to Hafnium Exploit?

Wagamama 21 Reputation points
2021-03-17T19:50:57.71+00:00

We have some Exchange Tools machines that have an CU on them. Unfortunately we cannot install a newer CU on them due to some software dependencies.

Are these machines vulnerable to the Hafnium exploits? There are no Exchange Services running on them at all and there is nothing listening on port 443 and the only website on port 80 is the default website which was created by the tools installation.

I understand there may be vulnerable files on there, I get it. But with the absence of Exchange Services running on these machines, do we have any concerns with the Hafnium Exploit where these machines are involved?

Thanks!

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,347 questions
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 141.5K Reputation points MVP
    2021-03-17T20:02:42.073+00:00

    No, if its JUST the Exchange tools, then you dont need to patch as there are none of the exploited virtual dirs are installed and the tools essentially use remoting to connect to the actual Exchange Servers. If anything you probably do not need to have the tools installed there at all really, but nonetheless, Exchange isnt "running" there.

    I'd still ensure there is anti-malware on them and ensure its not exposed to the internet of course :)

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. KyleXu-MSFT 26,206 Reputation points
    2021-03-18T09:13:22.37+00:00

    @Wagamama

    Exchange Tool is a remote control tool which doesn't hosted services, so it doesn't effected by Hafnium.

    I also test in my lab, we could use different CU for Exchange server and Exchange management tool:(The management tool is CU 18, the Exchange server is CU 20)
    79040-1-3.png

    There doesn't exist issue with them. So, you can update Exchange server to the lasted CU without updating the Exchange tool machines.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.