Microsoft Exchange vulnerable to PrivExchange zero-day
Summary
According to the researcher, the zero-day isnt one single flaw, but a combination of three (default) settings and mechanisms that an attacker can abuse to escalate his access from a hacked email account to the admin of the companys internal domain controller (a server that handles security authentication requests within a Windows domain). Microsoft Exchange servers are installed by default with access to many high privilege operations, meaning the attacker can use the Exchange servers newly compromised computer account to gain admin access on a companys Domain Controller, giving them the ability to create more backdoor accounts at will. The PrivExchange attack has been confirmed to work on Exchange and Windows Server DCs (Domain Controllers) running with fully-patched versions. However, Mollema has included several mitigations in his blog that system administrators can deploy to prevent attackers from exploiting this zero-day and getting control over their companies server infrastructure. It is both easy to carry out thanks to the availability of a ready-made proof-of-concept tool, but also because it grants attackers full control over a companys Windows IT infrastructure, the Holy Grail of most hacker groups.