ZDI-CAN-21462: ZDI-23-1646: Microsoft Exchange GsmWriter Deserialization of Untrusted Data NTLM Relay Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition or relay NTLM credentials on affected installations of Microsoft Exchange. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-38181.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21462?
ZDI-CAN-21462 has a CVSS rating of 8.8, indicating a high severity level.
What kind of attack does ZDI-CAN-21462 allow?
ZDI-CAN-21462 allows remote attackers to create a denial-of-service condition or relay NTLM credentials.
Is authentication required to exploit ZDI-CAN-21462?
Yes, authentication is required to exploit the ZDI-CAN-21462 vulnerability.
Which software is affected by ZDI-CAN-21462?
The ZDI-CAN-21462 vulnerability affects Microsoft Exchange installations.
How can I protect against ZDI-CAN-21462?
To protect against ZDI-CAN-21462, ensure that all affected Microsoft Exchange installations are updated with the latest security patches.