logo

Critical Exchange Server Flaw (CVE-2024-21410) Under Active Exploitation

ID: acec9330-ac4a-5c44-962c-9b48086b459e

STIX ID: report--acec9330-ac4a-5c44-962c-9b48086b459e

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-02-15

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Microsoft confirmed active exploitation of CVE-2024-21410, a critical (CVSS 9.8) Exchange Server privilege-escalation bug that can leak NTLM credentials and allow attackers to relay Net-NTLMv2 hashes to authenticate as users; fixes were issued and Microsoft set the Exploitability Assessment to "Exploitation Detected" and enabled Extended Protection for Authentication by default in recent updates. The report places this flaw alongside other recently patched, actively weaponized issues (CVE-2024-21351, CVE-2024-21412, CVE-2024-21413) and highlights potential abuse by state-affiliated actors like APT28 and Water Hydra.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.