Improper access control in Microsoft Exchange Server - CVE-2019-0686
Published: January 27, 2019 / Updated: February 12, 2019
Microsoft Exchange Server
Detailed vulnerability description
The vulnerability allows a remote authenticated user to gain escalated privileges.
The vulnerability exists due to improper access restrictions when processing requests to the "/privexchange" API endpoint. A remote authenticated user with limited privileges and mailbox access can gain DCSync privileges and obtain hashed passwords of all Active Directory users.