Modern Australian
The Times

Security flaws in Microsoft email software raise questions over Australia's cybersecurity approach

  • Written by Carsten Rudolph, Associate professor, Monash University
Security flaws in Microsoft email software raise questions over Australia's cybersecurity approach

On March 2, 2021, Microsoft published information about four critical vulnerabilities in its widely used Exchange email server software that are being actively exploited. It also released security updates for all versions of Exchange back to 2010.

Microsoft has told cybersecurity expert Brian Krebs it was notified of the vulnerabilities in “early January”. The Australian Cyber Security Centre has also issued a notice on the vulnerabilities.

The situation has been widely reported in the general media as well as specialist cybersecurity sites, but often inaccurately. But the situation also highlights a contradiction in government cybersecurity policy.

When governments find flaws in widely used software, they may not publish the details in order to build up their own offensive cybersecurity capabilities, i.e. the ability to target computers and networks for spying, manipulation and disruption. Operations like this often rely on exploiting vulnerabilities in commercial software — thus leaving their own citizens vulnerable to attack as a consequence.

What happened?

Microsoft has issued patches to fix the vulnerabilities and provided advice on how to respond if systems have already been affected.

These vulnerabilities can be really damaging for anybody running their own Exchange mail server. Attackers can run any code on the server and fully compromise a business’s email, allowing them to impersonate anybody in the business. They could also read all email stored on the server and potentially compromise more systems within the businesses’ network.

Who was affected?

It’s important to clear up exactly who the vulnerabilities affected: anybody running their own instance of Exchange, and the risk was higher if web access was turned on.

An ABC/Reuters report said:

All of those affected appear to run Web versions of email client Outlook and host them on their own machines, instead of relying on cloud providers.

But using a cloud-hosted version of Exchange wouldn’t necessarily solve the problem, as the vulnerabilities still exist. What’s more, larger enterprises will most probably still choose or be required by regulation to also run a local Exchange server that can be exploited in the same way.

Read more: 5 ways the COVID-19 pandemic has forever changed cybersecurity

Another open issue with moving mail servers to the cloud is that it also gives the provider access to all unencrypted emails by default. End-to-end encryption would increase security, but this is not currently standard practice.

Questions for Microsoft

As vulnerabilities existed in versions of the software released as long ago as 2010, we can assume more skilled attackers have already used them. This raises a fundamental question about the quality of the software, which Microsoft has been developing since 1996. Why did Microsoft not spot these vulnerabilities earlier?

Another question: if Microsoft knew about the vulnerabilities in early January, why did it take two months to alert its customers?

Questions for cybersecurity policy

We also need to consider the bigger picture of how we deal with vulnerabilities in software that builds the backbone of our computer and network infrastructure. Obviously, these vulnerabilities would have been a great offensive cybersecurity tool for any number of actors.

There is a basic conflict between building offensive cybersecurity capabilities and protecting our own businesses and citizens.

Imagine you are tasked with building offensive cybersecurity capabilities. You discover these vulnerabilities in Microsoft Exchange. Would you alert the vendor, Microsoft in this case, to make sure they are fixed as soon as possible, or would you keep them secret to not to lose your great new cyber weapon? Secretly having access to an organisation’s email could be very valuable for law enforcement or intelligence agencies.

Read more: The SolarWinds hack was all but inevitable – why national cyber defense is a 'wicked' problem and what can be done about it

Australia’s Cyber Security Strategy 2020 does not address the contradiction between establishing offensive cybersecurity capabilities and protecting Australians from cybersecurity vulnerabilities.

The establishment of offensive cybersecurity capabilities is explicitly mentioned in the strategy. In contrast, the detection of vulnerabilities with the goal of mitigation is not a clear goal.

Nor is openness about existing vulnerabilities — which would empower Australian citizens to react to them — part of the strategy. Australia has the expertise across the public sector, private sector and civil society to have this important dialogue on how to best protect Australian citizens and businesses.

Authors: Carsten Rudolph, Associate professor, Monash University

Read more https://theconversation.com/security-flaws-in-microsoft-email-software-raise-questions-over-australias-cybersecurity-approach-156864

Road Signs: Understanding Their Role in Clear and Effective Signage

Effective signage and display hardware can help businesses communicate information, promote products and organise customer or visitor movement. Road...

Bottle Label Printing: Key Factors to Consider Before Your Next Packaging Run

Effective packaging begins with understanding the product, bottle material, artwork and production requirements when planning bottle label printing. H...

Planning a Long-Distance Move With Interstate Movers Melbourne

Moving between states involves more planning than a typical local relocation. Along with packing and transporting household belongings, you need to...

Understanding the Role of an I/O Controller in Industrial Automation

Modern industrial systems depend on accurate communication between sensors, machines and control systems. An I/O controller can help manage this commu...

How the Right Mining Hose Supports Demanding Operations

Mining environments place considerable demands on equipment used for material transfer, water management and processing. Hoses operating in these co...

Simple Ideas for Making Social Gatherings More Memorable

We have all been to those parties where everyone just stands around the kitchen island, staring at their phones, waiting for someone else to make a mo...

Outdoor Wall Lights: Improving Exterior Lighting Around Your Home

Lighting can influence how a room looks, feels and functions, so the right fitting should be selected according to both appearance and practical req...

Commercial Office Cleaning: Combining Routine Office Cleaning With Melbourne Service

Keeping a workplace clean requires a service that can accommodate everyday tasks as well as the particular needs of the business. Professional comme...

Caravan Sales in Queensland: How to Find the Right Caravan for Sale QLD

Caravan ownership is about more than having somewhere to sleep while travelling. For many Queenslanders, it is one of the best ways to explore regio...

What Sir Walter Buffalo Turf Actually Costs in 2026 (And Why Quotes Vary So Much)

Two quotes landed on a Hills District homeowner's kitchen table last spring for the exact same 80-square-metre backyard. One said $12 a metre. The o...

Nearly 1,300 NSW Hospital Beds Are Occupied By People Who Are Ready To Go Home

1,276 people in NSW hospitals have been medically cleared for discharge but remain in hospital because they're still waiting for NDIS or aged care sup...

National Survey Launched to Measure Operational Impacts of Federal NDIS Policy Reforms

The effects of recent NDIS reforms are beginning to move beyond policy papers and into day to day service delivery. A new national survey is asking ...

Beyond the Nappy Cake: Baby Shower Gifts That Get Used

What new Australian parents unwrap, keep, and quietly thank you for months later. Six weeks after my daughter was born, I did an audit of the baby sh...

Parent-Advocates Are Reshaping Frontline Disability Service Delivery

Parents have always been part of the disability sector. They advocate, coordinate services, challenge decisions and often become the person holding ev...

Vista Cruises Enters "Two-Flagship Era" as Vista Aurora Completes Inaugural Voyage

Vista Aurora Sets Sail along the Yangtze. (Photo courtesy of the company)YICHANG, China — August 5, 2026 — Vista Aurora, a high-end interprovinc...

A Digital Preparation Checklist For International Medical Conferences

An international medical conference compresses many responsibilities into a few days. A delegate may need to present research, move between venues, ...

The Growing Popularity of Lab Grown Diamonds in Sydney and Hong Kong

The diamond industry has changed significantly in recent years as more buyers seek ethical, affordable, and sustainable alternatives to mined diamon...

Modern AI SEO Agency vs Traditional SEO: What’s the Difference

Search engine optimisation has changed dramatically over the past few years. Search engines have become smarter, user behaviour has evolved, and bus...