Get a Pentest and security assessment of your IT network.

Cyber Security

Microsoft Provides Mitigations, Workarounds for PrivExchange Vulnerability

Microsoft released a security advisory with mitigation measures and workarounds for an elevation of privilege vulnerability affecting Microsoft Exchange 2013 and newer. The vulnerability was made public by security researcher Dirk-jan Mollema, together with a proof-of-concept tool named PrivExchange. To exploit the vulnerability, an attacker would need to execute a man-in-the-middle attack to forward an authentication request to a Microsoft Exchange Server, thereby allowing impersonation of another Exchange user. This could come with some negative and unexpected behavior affecting users of EWS-powered apps such as Outlook for Mac, Skype for Business, notification reliant LOB applications and iOS native email clients.

Source: https://www.bleepingcomputer.com/news/security/microsoft-provides-mitigations-workarounds-for-privexchange-vulnerability/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security