LIVE MONITORING
High Advisory CVE-2024-21410

High: Microsoft Exchange Server Zero-Day Chain

Affected Systems

Microsoft Exchange Server 2016, 2019

Microsoft has disclosed a privilege escalation vulnerability in Exchange Server that allows attackers to relay NTLM credentials and impersonate users. The vulnerability is being actively exploited by nation-state actors.

Mitigation Steps

  1. Apply February 2024 security updates
  2. Enable Extended Protection for Authentication
  3. Monitor for NTLM relay attacks