Microsoft warned about a critical vulnerability in Exchange Server that was used as a zero-day, before it was patched in the Patch Tuesday released on Tuesday.

The flaw was discovered internally and is tracked as CVE-2024-21410. It allows remote unauthenticated users to gain elevated privileges for NTLM relay attacks targeting vulnerable versions of Microsoft Exchange Server.
In such attacks, the attacker forces a network (including servers or domain controllers) to authenticate against an NTLM relay server under their control, to impersonate the targeted devices and elevate privileges.
See also: Microsoft Patch Tuesday February 2024: 73 vulnerabilities fixed
" An attacker could target an NTLM client, such as Outlook, with an NTLM credentials-leaking type vulnerability ," Microsoft explains
“The leaked credentials can then be relayed to the Exchange server to gain privileges as the victim client and perform operations on the Exchange server on behalf of the victim.“.
Successful exploitation of the vulnerability could relay a user's Net-NTLMv2 hash to a vulnerable Exchange Server for user authentication .
Therefore, exploiting the CVE-2024-21410 vulnerability can lead to an increased security data. Threat actors can bypass security measures and gain access to sensitive information.
Additionally, exploiting this vulnerability could potentially allow attackers to attack other systems connected to the vulnerable server.
See also: Zoom: Warns of critical vulnerability – Update immediately!
Finally, exploiting this vulnerability can lead to a loss of trust from customers and partners, as a security breach can have serious implications for corporate reputation and credibility.

Exchange Extended Protection
The Exchange Server 2019 update (Cumulative Update 14 (CU14) update) addresses the security by enabling NTLM credentials Relay Protections (also known as Extended Protection for Authentication or EPA).
These protections enhance Windows Server authentication functionality by mitigating authentication relay and man-in-the-middle (MitM) attacks.
Microsoft announced yesterday that Extended Protection (EP) will be automatically enabled by default on all Exchange servers after installing this month's 2024 H1 Cumulative Update (aka CU14).
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: New vulnerabilities in Azure HDInsight Spark, Kafka, and Hadoop services
Administrators can use the ExchangeExtendedProtectionManagement PowerShell script to enable EP in earlier versions of Exchange Server to protect against potential exploitation of the CVE-2024-21410 vulnerability.
However, before implementing EP toggle on Exchange servers, administrators should assess their environments and review the issues listed in Microsoft's EP toggle script report. This review is necessary to avoid potential functionality issues.
Source: www.bleepingcomputer.com
