CERT-In Vulnerability Note
CIVN-2024-0049
Privilege Escalation Vulnerability in Microsoft Exchange Server
Original Issue Date:February 15, 2024
Severity Rating: CRITICAL
Software Affected
- Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Exchange Server 2019 Cumulative Update 13
- Microsoft Exchange Server 2016 Cumulative Update 23
Overview
A vulnerability has been reported in Microsoft Exchange Server, which could allow a remote attacker to gain elevated privileges on the targeted system.
Description
This vulnerability exists due to an error in Microsoft Exchange Server. An attacker could target an NTLM client such as Outlook with an NTLM credentials-leaking type vulnerability. The leaked credentials can then be relayed against the Exchange server to gain privileges as the victim client and to perform operations on the Exchange server on the victims behalf.
Note: This vulnerability (CVE-2024-21410 ) is being exploited in the wild.
Solution
Apply appropriate security updates as mentioned in the below link:
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21410
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21410
References
Microsoft
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21410
Bleeping Computer
https://www.bleepingcomputer.com/news/security/microsoft-new-critical-exchange-bug-exploited-as-zero-day/
CVE Name
CVE-2024-21410
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|