Over 28,500 Exchange servers vulnerable to actively exploited bug
ID: 44f06ac9-c72b-5c07-848b-32a32f12c609
STIX ID: report--44f06ac9-c72b-5c07-848b-32a32f12c609
Feed Name: Bleeping Computer
Threat Score
Critical Microsoft Exchange privilege-escalation vulnerability CVE-2024-21410, which enables NTLM relay attacks and can allow attackers to escalate privileges on Exchange servers, is being actively exploited; Shadowserver identified roughly 97,000 potentially vulnerable servers (28,500 confirmed). Administrators are urged to apply Exchange Server 2019 CU14 (NTLM Relay Protections) or other mitigations; CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
