Security Vulnerability in Microsoft Exchange Servers

More than 28,000 Exchange servers, Microsoft, which is vulnerable to actively exploited errors, fixed an actively exploited security vulnerability (bug), but 28,500 Exchange servers are still exposed.

22 Feb 2024 SintelSedat Akfidan 1 min read
Security Vulnerability in Microsoft Exchange Servers

Microsoft Exchange is being actively exploited by the CVE-2024-21410 security vulnerability. Although Microsoft resolved the issue on February 13, Shadowserver reports that 28,500 vulnerable servers were detected.

The vulnerability allows unauthenticated remote actors to perform NTLM relay attacks on Exchange servers and escalate privileges within the system. Shadowserver claims that 97,000 vulnerable servers could exist, with 68,500 of them being affected by the applied mitigations. 28,500 of these are effectively vulnerable to CVE-2024-21410.

However, there is still no general proof-of-concept for exploiting the vulnerability, which may reduce the number of attackers using it. CISA has added the vulnerability to its catalog of known exploited vulnerabilities and gave federal agencies in the US until March 7, 2024, to apply mitigations or stop using the product.

Source: More than 28,000 Exchange servers vulnerable to actively exploited bugs (itsecurity.pt)