logo

HAFNIUM__2021__HAFNIUM_targeting_Exchange_Servers_with_0-day_exploits_-_Microsoft_Security.pdf

ID: 738f3c4a-c389-4f45-a6d4-b3941a242b6b

STIX ID: report--738f3c4a-c389-4f45-a6d4-b3941a242b6b

Threat Score

92/100

Uploaded: 2026-08-15

Published Date: 2021-03-12

Last Modified Date: 2021-03-12

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Microsoft reports that the HAFNIUM group exploited multiple zero-day vulnerabilities in on-premises Exchange Server to gain unauthorized access, deploy web shells, dump LSASS memory, export mailbox data, and exfiltrate information; the advisory lists exploited CVEs, example web shell and post-exploitation commands, observable IOCs (file hashes, paths, filenames), and detection/hunting queries and mitigations, urging immediate patching and investigation.