Get a Pentest and security assessment of your IT network.

News

Abusing Exchange: One API call away from Domain Admin

In most organisations using Active Directory and Exchange servers, Exchange servers have such high privileges that being Administrator on an Exchange server is enough to escalate to Domain Admin. This attack is possible by default and while no patches are available at the point of writing, there are mitigations that can be applied to prevent this privilege escalation. There are 3 components which are combined to escalate from any user with a mailbox to domain Admin access: Exchange Servers have (too) high privileges by default. NTLM authentication is vulnerable to relay attacks instead of a reflection attack, we can grant ourselves DCSync rights.”]

Source: https://dirkjanm.io/abusing-exchange-one-api-call-away-from-domain-admin/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Google Chrome will block code injection from third-party software within 14 months