Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-35368: Microsoft Exchange Remote Code Execution Vulnerability

According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H), integrity (I:H) and availability (A:H). What does that mean for this vulnerability?

An attacker who successfully exploited this vulnerability could access a user’s Net-NTLMv2 hash which could be used as a basis of an NTLM Relay attack against another service to authenticate as the user.

Microsoft Security Response Center
#vulnerability#microsoft#rce#auth#Microsoft Exchange Server#Security Vulnerability

Microsoft Security Response Center: Latest News

CVE-2024-11395: Chromium: CVE-2024-11395 Type Confusion in V8