Close Menu
  • Home
  • Finance News
  • Personal Finance
  • Investing
  • Cards
    • Credit Cards
    • Debit
  • Insurance
  • Loans
  • Mortgage
  • More
    • Save Money
    • Banking
    • Taxes
    • Crime
What's Hot

Student loan borrowers at risk of wage garnishment in January

December 23, 2025

Michigan credit union blocks fraud with deepfake detection | Credit Union Journal

December 23, 2025

MBA Calls for Single Credit Report for a Mortgage If Your Credit Score is 700+

December 23, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Smart SpendingSmart Spending
Subscribe
  • Home
  • Finance News
  • Personal Finance
  • Investing
  • Cards
    • Credit Cards
    • Debit
  • Insurance
  • Loans
  • Mortgage
  • More
    • Save Money
    • Banking
    • Taxes
    • Crime
Smart SpendingSmart Spending
Home»Banking»Microsoft vulnerability affects certain Exchange users
Banking

Microsoft vulnerability affects certain Exchange users

August 9, 2025No Comments3 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
Microsoft vulnerability affects certain Exchange users
Share
Facebook Twitter LinkedIn Pinterest Email

Microsoft recently acknowledged a vulnerability affecting its email and calendar service Exchange that could allow an attacker to gain significant control over particular organizations’ email servers and, as a consequence, their cloud environments.

The vulnerability, discovered by cybersecurity researcher Dirk-jan Mollema with Outsider Security, specifically affects Microsoft Exchange Server hybrid deployments. In these setups, an organization uses both on-premises servers and the cloud-based Exchange Online, which is part of Microsoft 365.

Microsoft provided specific steps for mitigating the vulnerability, involving installing an update released in April and making a specific improvement to the security configuration of Exchange.

On Thursday, the Cybersecurity and Infrastructure Security Agency issued an emergency directive to federal agencies, indicating the disclosed vulnerability “poses grave risk to all organizations operating Microsoft Exchange hybrid-joined configurations.”

The agency said in the directive that while “exploitation of this vulnerability is only possible after an attacker establishes administrative access on the on-premises Exchange server,” the agency is “deeply concerned at the ease with which a threat actor could escalate privileges and gain significant control of a victim’s Microsoft 365 Exchange Online environment.”

How the vulnerability works

The vulnerability is a form of privilege escalation. This means an attacker who already has some level of access (like a compromised, low-privilege user account) within an organization’s network could exploit the situation to gain higher-level permissions.

The core issue is that an attacker could abuse the permissions of a predictable, preinstalled credential to move from a low-privilege position to a high-privilege one.

Although the preinstalled credential was meant to enable certain low-risk functionalities — for example, allowing users to show colleagues whether they are free or busy at a certain time, based on events in their Microsoft calendar — it had a vulnerability that could enable a threat actor to impersonate any user in the organization.

See also  What Affects Car Insurance Rates? These 7 Surprising Factors

An attack exploiting this vulnerability would go something like this:

First, gain a foothold. The attacker first compromises a regular user account within the organization, perhaps with a mass phishing attack that only one person would need to fall for.

Second, target the vulnerable credential by finding the service that uses it. This vulnerability involves Microsoft enabling hybrid Exchange users to set up a service that had the same identifier for all organizations, so an attacker would know exactly what to look for. The attacker could then analyze the permissions associated with that service, which by default were broader than strictly necessary.

Third, impersonate the service. The attacker could craft a malicious request, effectively pretending to be the hybrid service. They could abuse the trust relationship between Exchange on-premises and Exchange Online to request the vulnerable credential — an access token.

Fourth, escalate privileges. Using this token, the attacker could access data they weren’t authorized to see, such as reading other users’ emails or calendar information.

Steps to mitigate

Microsoft and CISA urged organizations, especially those in sensitive sectors like finance, to make specific reconfigurations to their hybrid Exchange setup to mitigate the vulnerability.

The first step is to install an update released in April that enables organizations to replace the vulnerable service with a more secure one. That update comes with a script for making this fix and thorough documentation on how to use it.

Second, run the script to replace the insecure service (known as a shared service principle) with the more secure service (known as a dedicated Exchange hybrid application). Or, if the organization does not need features such as allowing Exchange users to see others’ profile pictures, simply remove the insecure service without replacing it.

See also  Puerto Rican bank to appeal Fed master account closure case

Source link

Affects Exchange Microsoft users vulnerability
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
Previous ArticleHow Goldman Sachs aims to dominate another corner of Wall Street
Next Article Imposter scams cost older adults $700 million in 2024: FTC

Related Posts

Michigan credit union blocks fraud with deepfake detection | Credit Union Journal

December 23, 2025

Deposit insurance reform is about paychecks and communities

December 23, 2025

Let the market decide the future shape of banking in the US

December 23, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Guide to Comenity Bank-issued credit cards

November 14, 2024

Analysts’ stock picks for playing China’s 2025 consumer stimulus plan

January 12, 2025

9 Big Economic Developments and How They’ll Help (or Hurt) Your Finances in 2025

January 24, 2025
Ads Banner

Subscribe to Updates

Subscribe to Get the Latest Financial Tips and Insights Delivered to Your Inbox!

Stay informed with our finance blog! Get expert insights, money management tips, investment strategies, and the latest financial news to help you make smart financial decisions.

We're social. Connect with us:

Facebook X (Twitter) Instagram YouTube
Top Insights

Student loan borrowers at risk of wage garnishment in January

December 23, 2025

Michigan credit union blocks fraud with deepfake detection | Credit Union Journal

December 23, 2025

MBA Calls for Single Credit Report for a Mortgage If Your Credit Score is 700+

December 23, 2025
Get Informed

Subscribe to Updates

Subscribe to Get the Latest Financial Tips and Insights Delivered to Your Inbox!

© 2025 Smartspending.ai - All rights reserved.
  • Contact
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.