Man-in-the-middle attack in Microsoft Exchange Server - CVE-2018-8581
Published: November 13, 2018 / Updated: March 8, 2022
Microsoft Exchange Server
Detailed vulnerability description
The vulnerability exists due to use of a registry key exists called HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlLsa and lack of loopback check. A remote unauthenticated attacker can conduct a man-in-the-middle attack to forward an authentication request to a Microsoft Exchange Server, thereby allowing impersonation of another Exchange user and gain SYSTEM privileges.