#VU83067 Information disclosure in Microsoft Exchange Server - CVE-2023-36035
Published: November 14, 2023 / Updated: December 8, 2023
Microsoft Exchange Server
Microsoft
Description
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to an error within the IsUNCPath method in Microsoft Exchange server. A remote user on the local network can access a user's Net-NTLMv2 hash and perform NTLM Relay attack against another service to authenticate as the user.