ZDI-23-1640: Microsoft Exchange TransportConfigContainer Deserialization of Untrusted Data Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information or relay NTLM credentials on affected installations of Microsoft Exchange. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-36050.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1640?
The severity of ZDI-23-1640 is rated at 8.8, indicating a high risk to affected systems.
What type of information can be disclosed due to ZDI-23-1640?
ZDI-23-1640 allows remote attackers to disclose sensitive information and relay NTLM credentials.
Is authentication required to exploit ZDI-23-1640?
Yes, authentication is required to exploit the ZDI-23-1640 vulnerability.
What software is affected by ZDI-23-1640?
ZDI-23-1640 affects installations of Microsoft Exchange.
How can organizations mitigate ZDI-23-1640?
Organizations can mitigate ZDI-23-1640 by applying security patches and implementing appropriate configurations to secure Microsoft Exchange.