Lucene search

K
zdiPiotr Bazydlo (@chudypb) of Trend Micro Zero Day InitiativeZDI-23-1637
HistoryNov 15, 2023 - 12:00 a.m.

Microsoft Exchange IsUNCPath Improper Input Validation NTLM Relay Vulnerability

2023-11-1500:00:00
Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative
www.zerodayinitiative.com
5
microsoft exchange
isuncpath
input validation
ntlm relay
vulnerability
authentication

7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.4%

This vulnerability allows remote attackers to relay NTLM credentials on affected installations of Microsoft Exchange. Authentication is required to exploit this vulnerability. The specific flaw exists within the IsUNCPath method. The issue results from the lack of proper input validation. An attacker can leverage this vulnerability to relay NTLM credentials in the context of SYSTEM.

7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.4%