logo

Microsoft Exchange adds warning to emails abusing spoofing flaw

ID: 0ee8b48d-3044-57c0-8277-46bf911c9a4c

STIX ID: report--0ee8b48d-3044-57c0-8277-46bf911c9a4c

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2024-11-12

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft disclosed CVE-2024-49040, a high-severity Exchange Server flaw (affecting Exchange 2016 and 2019) that allows attackers to forge senders via malformed P2 FROM headers and parsing inconsistencies; Microsoft released November 2024 updates to detect exploitation and prepend warning banners and an X-MS-Exchange-P2FromRegexMatch header to suspicious emails, while advising administrators not to disable the protection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.