Elevation of Privilege Vulnerability Affects Microsoft Exchange Server

CVE-2024-21410
9.8CRITICAL

Key Information

Vendor
Microsoft
Status
Microsoft Exchange Server 2016 Cumulative Update 23
Microsoft Exchange Server 2019 Cumulative Update 13
Microsoft Exchange Server 2019 Cumulative Update 14
Vendor
CVE Published:
13 February 2024

Badges

😄 Trended👾 Exploit Exists📰 News Worthy

Summary

The Microsoft Exchange Server vulnerability CVE-2024-21410 has been actively exploited in attacks, allowing attackers to mount pass-the-hash attacks and gain privileges as the victim client to perform operations on the Exchange server. An attacker could exploit the bug to relay a user’s Net-NTLMv2 hash against a vulnerable server and authenticate as that user. The vulnerability has been addressed with the release of Exchange Server 2019 Cumulative Update 14. Check Point also published details on another critical-severity Outlook vulnerability, CVE-2024-21413, which allows attackers to bypass the Office Protected View and execute code remotely. Exploitation of this issue can lead to data theft, malware execution, privilege escalation, and victim impersonation. Both individual users and organizations are advised to apply any patches or security updates provided by Microsoft, to follow recommended security practices, and to remain vigilant against suspicious hyperlinks and emails.

CISA Reported

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2024-21410 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Affected Version(s)

Microsoft Exchange Server 2016 Cumulative Update 23 =

Microsoft Exchange Server 2019 Cumulative Update 13 < 15.2.1544.004

Microsoft Exchange Server 2019 Cumulative Update 14 < 15.2.1544.004

News Articles

EPSS Score

7% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit exists.

  • Vulnerability started trending.

  • First article discovered by ÇözümPark

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre DatabaseCISA DatabaseMicrosoft Feed0 Proof of Concept(s)10 News Article(s)
.