ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft Exchange flaw CVE-2024

criticalRansomware exploited in the wildimportance 60CVE-2024-21410

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-21410
Privilege Escalation via NTLM Relay Flaw in Microsoft Exchange Server

CVE-2024-21410 is a critical improper authentication flaw (CWE-287, CVSS 9.8) in on-premises Microsoft Exchange Server that enables NTLM credential relay attacks against the server's authentication, for example over SMTP. An attacker who can induce an NTLM authentication exchange can relay captured credentials to Exchange and impersonate another user, achieving an elevation of privilege without holding valid credentials themselves. Organizations running vulnerable on-premises Exchange — particularly internet-facing servers where Extended Protection for Authentication is not enforced — are affected. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-02-15, and the fix shipped in Microsoft's February 2024 Patch Tuesday release alongside roughly 90 other vulnerabilities; no public proof-of-concept code is known.

Do: Apply Microsoft's February 2024 Exchange Server security update immediately, prioritizing internet-facing servers; note that the update enables Extended Protection for Authentication (EPA) by default, so verify EPA is active and that clients, appliances, and load balancers relying on NTLM/SMTP authentication still function. Because the flaw is on CISA's KEV catalog, federal and high-risk operators must apply the vendor mitigations promptly or discontinue use if patching is not possible.

9.813% KEV
  • microsoft exchange server
large≈100,000 internet-exposed Exchange servers worldwide (public scan-based reporting; BSI counted 17,000+ in Germany alone)
Full article376 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 21, 2024

Researchers from Shadowserver Foundation identified roughly 28,000 internet-facing Microsoft Exchange servers vulnerable to CVE-2024-21410.

The vulnerability CVE-2024-21410 is a bypass vulnerability that can be exploited by an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution, which could lead to some data exposure, lack of system availability, or both.

“An attacker could target an NTLM client such as Outlook with an NTLM credentials-leaking type vulnerability. The leaked credentials can then be relayed against the Exchange server to gain privileges as the victim client and to perform operations on the Exchange server on the victim’s behalf. For more information about Exchange Server’s support for Extended Protection for Authentication(EPA), please see Configure Windows Extended Protection in Exchange Server.” reads the advisory published by Microsoft.

The IT giant addressed the issue with the release of Patch Tuesday security updates for February 2024.

Last week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. Microsoft also updated its advisory to label the flaw as actively exploited in the wild.

On 2024-02-17 Shadowserver researchers identified around 97K vulnerable or possibly vulnerable (vulnerable version but may have mitigation applied).

Out of 97,000 servers, 28,500 have been verified to be vulnerable to CVE-2024-21410.

Most of these servers are in Germany, followed by the United States. Below are the data shared by Shadowserver:

Data shared in our Vulnerable Exchange Server report – https://t.co/ApcM9HwiOK

Count of vulnerable instances on 2024-02-17: 28.5K

Count of possibly vulnerable instances on 2024-02-17: 68.5K

Please note this vulnerability is on the CISA KEV – https://t.co/bUYwEMNRY9

— The Shadowserver Foundation (@Shadowserver) February 19, 2024
CountryCounted IP addresses
Germany25,695
United States21,997
United Kingdom4,130
Netherlands3,505
France3,381
Austria3,337
Russia3,069
Canada2,891
Switzerland2,404
Australia2,148
Italy2,048
Czechia1,392
China1,221
Belgium919
Turkey881
Taiwan870
Hong Kong742
Hungary624
Spain570
South Africa563

However, the researchers warn that the above results were calculated by summing counts of unique IPs, which means that a “unique” IP may have been counted more than once.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – ransomware, Microsoft Exchange) 



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/159424/hacking/28000-vulnerable-microsoft-exchange-servers.html