ZeroHour

CVE-2024-21410

KEVlarge1

Privilege Escalation via NTLM Relay Flaw in Microsoft Exchange Server

CISA: Microsoft Exchange Server Privilege Escalation Vulnerability

CVSS 3.1
9.8 critical
EPSS
13%p96
Published
()
KEV added
AI analysis

CVE-2024-21410 is a critical improper authentication flaw (CWE-287, CVSS 9.8) in on-premises Microsoft Exchange Server that enables NTLM credential relay attacks against the server's authentication, for example over SMTP. An attacker who can induce an NTLM authentication exchange can relay captured credentials to Exchange and impersonate another user, achieving an elevation of privilege without holding valid credentials themselves. Organizations running vulnerable on-premises Exchange — particularly internet-facing servers where Extended Protection for Authentication is not enforced — are affected. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-02-15, and the fix shipped in Microsoft's February 2024 Patch Tuesday release alongside roughly 90 other vulnerabilities; no public proof-of-concept code is known.

What to do: Apply Microsoft's February 2024 Exchange Server security update immediately, prioritizing internet-facing servers; note that the update enables Extended Protection for Authentication (EPA) by default, so verify EPA is active and that clients, appliances, and load balancers relying on NTLM/SMTP authentication still function. Because the flaw is on CISA's KEV catalog, federal and high-risk operators must apply the vendor mitigations promptly or discontinue use if patching is not possible.

Affected
microsoft exchange server
Estimated exposure
large≈100,000 internet-exposed Exchange servers worldwide (public scan-based reporting; BSI counted 17,000+ in Germany alone) — Estimate derived from internet-wide scan reporting of vulnerable Exchange servers — Germany's BSI alone warned of over 17,000 unpatched servers, implying a global exposed population on the order of 100,000 on-premises systems.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Exchange Server Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Exchange Server
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
exchange server
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news