Improper Authentication in Microsoft Exchange Server - CVE-2019-1136
Published: July 10, 2019
Microsoft Exchange Server
Detailed vulnerability description
The vulnerability allows a remote attacker to escalate privileges within the Microsoft Exchange Server.
The vulnerability exists within the Exchange Web Services (EWS) feature when processing authentication tokens. A remote attacker with ability to perform man-in-the-middle (MitM) attack and forward the authentication request to Exchange server can impersonate victim and gain unauthorized access to the server.