ZDI-23-1641: Microsoft Exchange FederationTrust Deserialization of Untrusted Data NTLM Relay Vulnerability
Published Nov 15, 2023
·Updated
This vulnerability allows remote attackers to relay NTLM credentials on affected installations of Microsoft Exchange. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-36039.
Affected Software
1 affected component
Microsoft Exchange
Event History
Nov 15, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1641?
The severity of ZDI-23-1641 is rated at 8.8 according to the CVSS.
2
How do I fix ZDI-23-1641?
To fix ZDI-23-1641, apply the latest security updates provided by Microsoft for Exchange.
3
What does ZDI-23-1641 exploit allow attackers to do?
ZDI-23-1641 allows remote attackers to relay NTLM credentials on affected installations of Microsoft Exchange.
4
Is authentication required to exploit ZDI-23-1641?
Yes, authentication is required to exploit ZDI-23-1641.
5
What CVE is associated with ZDI-23-1641?
The CVE associated with ZDI-23-1641 is CVE-2023-36039.