Man-in-the-middle attack in Microsoft Exchange Server - CVE-2018-8581
Published: November 13, 2018 / Updated: March 8, 2022
Vulnerability details
The vulnerability exists due to use of a registry key exists called HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlLsa and lack of loopback check. A remote unauthenticated attacker can conduct a man-in-the-middle attack to forward an authentication request to a Microsoft Exchange Server, thereby allowing impersonation of another Exchange user and gain SYSTEM privileges.