logo

Microsoft Exchange vulnerability actively exploited

ID: a05fbf51-29f5-58c8-8cda-2936aa815f11

STIX ID: report--a05fbf51-29f5-58c8-8cda-2936aa815f11

Feed Name: Malwarebytes Blog

Threat Score
90/100

Date Published: 2024-02-16

Date Updated: 2026-04-28

...
...

Microsoft Exchange vulnerability CVE-2024-21410 (CVSS 9.8) is being actively exploited to leak NTLM credentials from clients (e.g., Outlook), which can be relayed against Exchange servers to gain privileges and perform actions on behalf of victims; Microsoft and the German BSI have issued warnings and Microsoft recommends installing the latest cumulative updates and enabling Extended Protection for Authentication to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.