Around 9700 Microsoft Exchange Servers Affected by Privilege Escalation Vulnerability
ID: 26793946-7a57-5b8c-99ee-b0a6a0d2ac4b
STIX ID: report--26793946-7a57-5b8c-99ee-b0a6a0d2ac4b
Feed Name: Censys Blog
Threat Score
The report details CVE-2019-1136, an Exchange Server elevation-of-privilege vulnerability involving EWS and NTLM token handling that could allow mailbox impersonation via a man-in-the-middle attack; it shows how to use Censys X-OWA-Version header searches to identify affected servers and reports roughly 9,700 potentially vulnerable instances, while noting Microsoft updated EWS NTLM handling and no known public exploits existed at publication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
