Microsoft Exchange vulnerable to PrivExchange zero-day

General News

Summary

According to the researcher, the zero-day isnt one single flaw, but a combination of three (default) settings and mechanisms that an attacker can abuse to escalate his access from a hacked email account to the admin of the companys internal domain controller (a server that handles security authentication requests within a Windows domain). Microsoft Exchange servers are installed by default with access to many high privilege operations, meaning the attacker can use the Exchange servers newly compromised computer account to gain admin access on a companys Domain Controller, giving them the ability to create more backdoor accounts at will. The PrivExchange attack has been confirmed to work on Exchange and Windows Server DCs (Domain Controllers) running with fully-patched versions. However, Mollema has included several mitigations in his blog that system administrators can deploy to prevent attackers from exploiting this zero-day and getting control over their companies server infrastructure. It is both easy to carry out thanks to the availability of a ready-made proof-of-concept tool, but also because it grants attackers full control over a companys Windows IT infrastructure, the Holy Grail of most hacker groups.

Classifications

industries
No industries detected
applications
Accounting and Taxes

AskAI Classifications

Labels
Developer Tools DevOps Software SaaS

Linked Companies

GitHub, Inc.
$1M to $5M
Microsoft
$1B+