Microsoft Exchange vulnerability actively exploited
ID: a05fbf51-29f5-58c8-8cda-2936aa815f11
STIX ID: report--a05fbf51-29f5-58c8-8cda-2936aa815f11
Feed Name: Malwarebytes Blog
Threat Score
Microsoft Exchange vulnerability CVE-2024-21410 (CVSS 9.8) is being actively exploited to leak NTLM credentials from clients (e.g., Outlook), which can be relayed against Exchange servers to gain privileges and perform actions on behalf of victims; Microsoft and the German BSI have issued warnings and Microsoft recommends installing the latest cumulative updates and enabling Extended Protection for Authentication to mitigate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
