ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews1

Critical Exchange Server Flaw (CVE-2024

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-21412
+1 in the same advisory: …21351
CVE-2024-21412: Security Feature Bypass in Microsoft Windows Internet Shortcut Files

CVE-2024-21412 is a security feature bypass (CWE-693) in how Microsoft Windows handles Internet Shortcut files: a crafted shortcut can make Windows skip the security warning prompt that normally appears before untrusted internet content is opened or downloaded. Triggering it requires user interaction — an attacker must deliver a malicious shortcut file, typically via email or a malicious website, and convince the user to open it, which is reflected in the CVSS vector's UI:R component. An attacker who succeeds gains a bypass of those prompts, making it easier to retrieve and execute malicious remote content with fewer warnings; the DarkGate malware operators used exactly this technique in zero-day campaigns to distribute their loader. Anyone running the affected Windows 10 (1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), Windows Server 2019, or Windows Server 2022 (including 23H2) builds was exposed. The flaw was patched in Microsoft's February 2024 Patch Tuesday release (2024-02-13), the same day CISA added it to the KEV catalog, and it is under active exploitation with known ransomware association and a 95.4% EPSS score.

Do: Apply the February 2024 Windows cumulative security update (released 2024-02-13) or any later monthly cumulative update to every affected Windows 10, Windows 11, Windows Server 2019, and Windows Server 2022 build, and verify patch levels through your endpoint inventory. Because exploitation requires user interaction, as an interim control flag or block .url/Internet Shortcut attachments at email gateways and remind users not to open shortcuts from untrusted sources. Prioritize internet-facing and shared endpoints given the KEV listing and known ransomware use.

8.1
group max
95% KEV ransomware
  • microsoft Windows 10 1809, 21H2, 22H2
  • microsoft Windows 11 21H2, 22H2, 23H2
  • microsoft Windows Server 2019 all supported editions
  • +1 more
mass≈1 billion Windows 10/11/Server installations potentially affected worldwide (pre-patch installed base)
CVE-2024-21410
Privilege Escalation via NTLM Relay Flaw in Microsoft Exchange Server

CVE-2024-21410 is a critical improper authentication flaw (CWE-287, CVSS 9.8) in on-premises Microsoft Exchange Server that enables NTLM credential relay attacks against the server's authentication, for example over SMTP. An attacker who can induce an NTLM authentication exchange can relay captured credentials to Exchange and impersonate another user, achieving an elevation of privilege without holding valid credentials themselves. Organizations running vulnerable on-premises Exchange — particularly internet-facing servers where Extended Protection for Authentication is not enforced — are affected. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-02-15, and the fix shipped in Microsoft's February 2024 Patch Tuesday release alongside roughly 90 other vulnerabilities; no public proof-of-concept code is known.

Do: Apply Microsoft's February 2024 Exchange Server security update immediately, prioritizing internet-facing servers; note that the update enables Extended Protection for Authentication (EPA) by default, so verify EPA is active and that clients, appliances, and load balancers relying on NTLM/SMTP authentication still function. Because the flaw is on CISA's KEV catalog, federal and high-risk operators must apply the vendor mitigations promptly or discontinue use if patching is not possible.

9.813% KEV
  • microsoft exchange server
large≈100,000 internet-exposed Exchange servers worldwide (public scan-based reporting; BSI counted 17,000+ in Germany alone)
CVE-2024-21413
Improper Input Validation RCE in Microsoft Outlook (MonikerLink)

CVE-2024-21413 is an improper input validation flaw (CWE-20) in Microsoft Outlook, publicly dubbed "MonikerLink", in which Outlook mishandles a specially crafted hyperlink (a file:// moniker link) and bypasses the security prompt normally applied before opening such links. The flaw is triggered when a user opens or clicks a maliciously crafted link in an email, causing Outlook to invoke the target outside its protected handling. A successful attack can leak the user's NTLM credentials and can achieve remote code execution in the context of the current user; the flaw carries a critical CVSS 3.1 score of 9.8. Anyone running affected Outlook clients — Microsoft 365 Apps, Office 2016, Office 2019, and Office LTSC — is exposed, and the issue was fixed in Microsoft's February 2024 Patch Tuesday release. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-02-06, EPSS assigns a ~95% exploitation probability (100th percentile), and a public PoC is available.

Do: Apply Microsoft's February 2024 (or later) security updates for Microsoft 365 Apps, Office 2016, Office 2019, and Office LTSC, and verify Outlook builds are current, per the KEV required action to apply vendor mitigations or discontinue use. As interim mitigation, restrict outbound SMB/NTLM from endpoints (e.g., block outbound port 445 or disable NTLM where feasible) to blunt credential leakage from crafted file:// links. Hunt for signs of exploitation, such as unexpected outbound SMB connections or NTLM authentication events following users clicking links in email.

9.895% KEV PoC
  • Microsoft 365 Apps (Outlook)
  • microsoft Office 2016 (Outlook) all builds prior to the February 2024 security updates
  • microsoft Office 2019 (Outlook) all builds prior to the February 2024 security updates
  • +1 more
masshundreds of millions of users
Full article569 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananFeb 15, 2024Threat Intelligence / Vulnerability

Microsoft on Wednesday acknowledged that a newly disclosed critical security flaw in Exchange Server has been actively exploited in the wild, a day after it released fixes for the vulnerability as part of its Patch Tuesday updates.

Tracked as CVE-2024-21410 (CVSS score: 9.8), the issue has been described as a case of privilege escalation impacting the Exchange Server.

"An attacker could target an NTLM client such as Outlook with an NTLM credentials-leaking type vulnerability," the company said in an advisory published this week.

"The leaked credentials can then be relayed against the Exchange server to gain privileges as the victim client and to perform operations on the Exchange server on the victim's behalf."

Successful exploitation of the flaw could permit an attacker to relay a user's leaked Net-NTLMv2 hash against a susceptible Exchange Server and authenticate as the user, Redmond added.

The tech giant, in an update to its bulletin, revised its Exploitability Assessment to "Exploitation Detected," noting that it has now enabled Extended Protection for Authentication (EPA) by default with the Exchange Server 2019 Cumulative Update 14 (CU14) update.

Details about the nature of the exploitation and the identity of the threat actors that may be abusing the flaw are currently unknown. However, Russian state-affiliated hacking crews such as APT28 (aka Forest Blizzard) have a history of exploiting flaws in Microsoft Outlook to stage NTLM relay attacks.

Earlier this month, Trend Micro implicated the adversary to NTLM relay attacks targeting high-value entities at least since April 2022. The intrusions targeted organizations dealing with foreign affairs, energy, defense, and transportation, as well as those involved with labor, social welfare, finance, parenthood, and local city councils.

CVE-2024-21410 adds to two other Windows flaws – CVE-2024-21351 (CVSS score: 7.6) and CVE-2024-21412 (CVSS score: 8.1) – that have been patched by Microsoft this week and actively weaponized in real-world attacks.

The exploitation of CVE-2024-21412, a bug that enables a bypass of Windows SmartScreen protections, has been attributed to an advanced persistent threat dubbed Water Hydra (aka DarkCasino), which has previously leveraged zero-days in WinRAR to deploy the DarkMe trojan.

"The group used internet shortcuts disguised as a JPEG image that, when selected by the user, allows the threat actor to exploit CVE-2024-21412," Trend Micro said. "The group can then bypass Microsoft Defender SmartScreen and fully compromise the Windows host as part of its attack chain."

Microsoft's Patch Tuesday update also addresses CVE-2024-21413, another critical shortcoming affecting the Outlook email software that could result in remote code execution by trivially circumventing security measures such as Protected View.

Codenamed MonikerLink by Check Point, the issue "allows for a wide and serious impact, varying from leaking of local NTLM credential information to arbitrary code execution."

The vulnerability stems from the incorrect parsing of "file://" hyperlinks, which makes it possible to achieve code execution by adding an exclamation mark to URLs pointing to arbitrary payloads hosted on attacker-controlled servers (e.g., "file:///\\10.10.111.111\test\test.rtf!something").

"The bug not only allows the leaking of the local NTLM information, but it may also allow remote code execution and more as an attack vector," the cybersecurity firm said. "It could also bypass the Office Protected View when it's used as an attack vector to target other Office applications."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/02/critical-exchange-server-flaw-cve-2024.html