Microsoft has disclosed a serious Exchange Server vulnerability that allows attackers to spoof legitimate email senders and make malicious messages much more effective.

The vulnerability is tracked as CVE-2024-49040 and affects Exchange Server 2016 and 2019. It was discovered by Solidlab security researcher Vsevolod Kokorin .
“The problem is that SMTP servers parse the recipient’s address differently, which leads to email spoofing,” said in a May report.
See also: The 15 vulnerabilities most used in attacks in 2023
“Another issue I discovered is that some email providers allow the use of the < and > symbols in group names, which is not RFC compliant… During my research, I did not find a single email provider that parses the ‘From’ field correctly according to RFC standards,” he added.
Microsoft warned that the vulnerability could be used in attacks spoofing targeting Exchange servers. As a result, it released several updates during November's Patch Tuesday to add warning banners.
“The vulnerability is caused by the current implementation of P2 FROM header verification,” Microsoft explained.
“The current implementation allows the passage of some P2 FROM headers that are not compliant with RFC 5322, which can lead the email client (for example, Microsoft Outlook) to display a fake sender as if it were legitimate“.
Microsoft fixed the vulnerability in Patch Tuesday November 2024.
Exploit detection and email alerts will be enabled by default on all systems where administrators enable security from default settings.
See also: Microsoft Patch Tuesday November 2024: Fixes 91 vulnerabilities
Updated Exchange servers will also add a warning in the body of emails that a spoofed sender is detected and an X-MS-Exchange-P2FromRegexMatch header, to allow administrators to reject phishing emails that attempt to exploit the vulnerability.
“Notice: This email appears to be suspicious. Do not trust the information, links, or attachments in this message without verifying the source through a trusted method,” the warning states.

Microsoft Patch Tuesday November 2024
Yesterday, Microsoft released Patch Tuesday November 2024, which fixes 91 vulnerabilities, including the vulnerability mentioned above.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Four of the vulnerabilities have been categorized as critical: two allow remote code execution and two allow elevation of privilege.
See also: HPE patches vulnerabilities in Aruba Networking Access Points
In the list below you can see in detail the types of vulnerabilities fixed in Microsoft Patch Tuesday November:
- 52 vulnerabilities that allow remote code execution
- 26 vulnerabilities that allow for elevation of privilege
- 4 vulnerabilities that allow Denial of Service attacks
- 3 vulnerabilities that allow spoofing
- 2 vulnerabilities that allow bypassing security
- 1 vulnerability that allows information disclosure
Source: www.bleepingcomputer.com
