Email Autoresponder Free

Main Menu

  • Home
  • Email accounts
  • Email marketing
  • Email newsletter
  • Email verifier

Email Autoresponder Free

Header Banner

Email Autoresponder Free

  • Home
  • Email accounts
  • Email marketing
  • Email newsletter
  • Email verifier
Email accounts
Home›Email accounts›Exchange Server bug puts email accounts at risk

Exchange Server bug puts email accounts at risk

By Michael E. McChristian
August 31, 2021
0
0

A vulnerability in Microsoft Exchange Server can be used to compromise email accounts managed by the email platform, according to the Zero Day Initiative (ZDI), which urges Exchange Server users to install the patch released by Microsoft last month.

ZDI said the vulnerability, known as ProxyToken or CVE-2021-33766, can be exploited to “perform configuration actions on mailboxes owned by arbitrary users.” This might not sound particularly serious, but ZDI cited the ability to “copy all emails addressed to a target and account and forward them to an account controlled by the attacker” as an example of how the exploit could be used.

The fault lies in the Exchange Server architecture. ZDI said the platform sets up two websites: a front-end site that users interact with and a main site that allows the service to operate. The front end doesn’t handle anything involving authentication; this responsibility is transferred to the main site. ProxyToken abuses this configuration to bypass authentication.

ZDI has shared a proof-of-concept exploit that can be used to automatically forward all email from an Exchange user to a different account. This particular exploit requires the attacker to have an Exchange account on the same server as their victim, which limits its potential impact, but the organization noted that other ProxyToken exploits would not have the same requirements.

“On some Exchange installations,” ZDI said, “an administrator may have set a global configuration value that allows forwarding rules with arbitrary Internet destinations, and in this case the attacker does not need any information Exchange Credential”.

ZDI said ProxyToken was leaked by VNPT ISC researcher Le Xuan Tuyen in March; Microsoft released a patch related to the vulnerability in July. Exchange Server customers should install this patch, which was included with that month’s Cumulative Platform Updates, if they want to prevent attackers from exploiting the security flaw to access their email .

Recommended by our editors

This is just the latest in a series of Exchange Server vulnerabilities revealed in recent months. Devcore researcher Orange Tsai has been particularly active in disclosing a number of security flaws collected under the names ProxyLogon, ProxyOracle, and ProxyShell since the Pwn2Own 2021 hack contest in April. Now others have joined the cause.

“Exchange Server continues to be a surprisingly fertile area for vulnerability research,” ZDI said. “This can be attributed to the enormous complexity of the product, both in terms of feature set and architecture. We look forward to receiving additional vulnerability reports in the future from our talented researchers working in this domain.”

Security Watch newsletter for our top privacy and security stories delivered right to your inbox.","first_published_at":"2021-09-30T21:22:09.000000Z","published_at":"2021-09-30T21:22:09.000000Z","last_published_at":"2021-09-30T21:22:03.000000Z","created_at":null,"updated_at":"2021-09-30T21:22:09.000000Z"})" x-show="showEmailSignUp()" class="rounded bg-gray-lightest text-center md:px-32 md:py-8 p-4 font-brand mt-8 container-xs">
Do you like what you read ?

Register for Security Watch newsletter for our top privacy and security stories delivered straight to your inbox.

This newsletter may contain advertisements, offers or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You can unsubscribe from newsletters at any time.

Tagsemail accounts

Categories

  • Email accounts
  • Email marketing
  • Email newsletter

Recent Posts

  • How to start an email newsletter
  • Email Marketing and Marketing Automation: The Differences Explained
  • 4 Ways to Use Video in Your Email Marketing Campaigns
  • 5 Best ConvertKit Alternatives for Email Marketing Campaigns
  • Here’s why email marketing is (still) important in 2022

Archives

  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • September 2020
  • June 2020
  • May 2020
  • December 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • March 2018
  • January 2018
  • September 2017
  • November 2016
  • July 2016
  • October 2015
  • April 2015
  • July 2014
  • March 2014
  • June 2013
  • September 2011
  • July 2011
  • Privacy Policy
  • Terms and Conditions