logo

Microsoft: New critical Exchange bug exploited as zero-day

ID: 4bb7032a-fdcd-5c47-8919-2c1217d180de

STIX ID: report--4bb7032a-fdcd-5c47-8919-2c1217d180de

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-02-14

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft disclosed that CVE-2024-21410, a critical Exchange Server flaw allowing NTLM relay-based privilege escalation and impersonation, was exploited in the wild prior to being fixed; Microsoft addressed it by enabling Extended Protection for Authentication (EPA) in Exchange CU14/H1 and recommends administrators evaluate and apply EPA or use the ExchangeExtendedProtectionManagement script while being mindful of potential compatibility impacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.