ZDI-CAN-21983: ZDI-23-1637: Microsoft Exchange IsUNCPath Improper Input Validation NTLM Relay Vulnerability
Published Nov 15, 2023
·Updated
This vulnerability allows remote attackers to relay NTLM credentials on affected installations of Microsoft Exchange. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-36035.
Affected Software
1 affected component
Microsoft Exchange
Event History
Nov 15, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-21983?
ZDI-CAN-21983 has a CVSS rating of 8.8, indicating a high severity vulnerability.
2
How do I fix ZDI-CAN-21983?
To mitigate ZDI-CAN-21983, ensure that your Microsoft Exchange installations are updated to the latest security patches released by Microsoft.
3
What type of attack is associated with ZDI-CAN-21983?
ZDI-CAN-21983 is associated with remote attackers relaying NTLM credentials on affected Microsoft Exchange installations.
4
Is authentication required to exploit ZDI-CAN-21983?
Yes, authentication is required to exploit the ZDI-CAN-21983 vulnerability.
5
What software is affected by ZDI-CAN-21983?
ZDI-CAN-21983 affects installations of Microsoft Exchange.