Improper access control in Microsoft Exchange Server - CVE-2019-0724

 

Improper access control in Microsoft Exchange Server - CVE-2019-0724

Published: February 12, 2019 / Updated: October 29, 2019


Vulnerability identifier: #VU17588
CSH Severity: Medium
CVSS v4: 9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2019-0724
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote authenticated user to gain escalated privileges.

The vulnerability exists due to improper access restrictions within Exchange Web Services (EWS). A remote authenticated user with limited privileges and mailbox access can perform man-in-the-moddle (MitM)  attack to forward an authentication request to a Microsoft Active Directory domain controller and gain elevated privileges on the domain controller.

Successful exploitation of the vulnerability may allow an attacker to gain full access to the Active Directory infrastructure.

Affected software

Microsoft Exchange Server

How to mitigate CVE-2019-0724

Install updated from vendor's website.



Microsoft Exchange Server - addressed in versions 2010 Service Pack 3 Update Rollup 26, 2013 Cumulative Update 22 15.00.1473.003, 2016 Cumulative Update 12 15.01.1713.005, 2019 Cumulative Update 1 15.02.0330.005

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins