ZDI-CAN-22002: ZDI-23-1641: Microsoft Exchange FederationTrust Deserialization of Untrusted Data NTLM Relay Vulnerability
Published Nov 15, 2023
·Updated
This vulnerability allows remote attackers to relay NTLM credentials on affected installations of Microsoft Exchange. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-36039.
Affected Software
1 affected component
Microsoft Exchange
Event History
Nov 15, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-22002?
The severity of ZDI-CAN-22002 is rated at 8.8 on the CVSS scale.
2
How do I fix ZDI-CAN-22002?
To fix ZDI-CAN-22002, ensure that your Microsoft Exchange is updated to the latest security patch provided by Microsoft.
3
What is the impact of ZDI-CAN-22002?
ZDI-CAN-22002 allows remote attackers to relay NTLM credentials, potentially compromising authentication.
4
Is authentication required to exploit ZDI-CAN-22002?
Yes, authentication is required to exploit ZDI-CAN-22002.
5
Which software is affected by ZDI-CAN-22002?
ZDI-CAN-22002 affects installations of Microsoft Exchange.