A massive security hole has been discovered that means most Microsoft Exchange Servers 2013 and above can be hacked. This move would give criminals full Domain Controller administrator privileges, allowing them to create accounts on the targetserverat will.

In fact, all that is needed for the PrivExchange attack is the email and password of a user's mailbox, and in some cases even that is not needed. Hackers are able to compromise the server using a combination of three vulnerabilities. The specific vulnerabilities are analyzed below:
- Microsoft Exchange Servers have a feature called Exchange Web Services (EWS), which can be exploited by attackers to authenticate Exchange servers to a website controlled by an attacker, with an Exchange server computer account.
- This authentication is accomplished using NTLM hashes sent over HTTP and the Exchange server fails to set the Sign and Seal flags for NTLM operation, leaving NTLM authentication vulnerable to relay attacks and allowing the attacker to obtain the Exchange Server's NTLM hash.
- Microsoft Exchange Servers are installed by default with access to many privileged functions. This means that an attacker can use the newly compromised Exchange server computer account to gain administrative access to a company's Domain Controller, allowing them to create multiple backdoor accounts.
This particular attack has been confirmed to work on Exchange and Windows Server DCs (Domain Controllers) running fully upgraded versions. Microsoft has not announced any immediate update for the vulnerability but is expected to do so soon.
