Unknown 📢 Publicly disclosed 2019-02 archive

Executive Summary

An elevation of privilege vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server. To exploit the vulnerability, an attacker would need to execute a man-in-the-middle attack to forward an authentication request to a Microsoft Exchange Server, thereby allowing impersonation of another Exchange user. To address this vulnerability, a Throttling Policy for EWSMaxSubscriptions could be defined and applied to the organization with a value of zero. This will prevent the Exchange server from sending EWS notifications, and prevent client applications which rely upon EWS notifications from functioning normally. Examples of impacted applications include Outlook for Mac, Skype for Business, notification reliant LOB applications, and some iOS native mail clients. Please see Throttling Policy, for more information. An example: New-ThrottlingPolicy -Name AllUsersEWSSubscriptionBlockPolicy -EwsMaxSubscriptions 0 -ThrottlingPolicyScope Organization A planned update is in development. If you determine that your system is at high risk then you should evaluate the proposed workaround. After installing the update you can undo the above action with this command: Remove-ThrottlingPolicy -Identity AllUsersEWSSubscriptionBlockPolicy

Overview

Unknown
MS Severity
Not Exploited
MS Exploit Status
More Likely
MS Exploit Likelihood
Category Elevation of Privilege
Released Feb 12 2019
Last Updated Feb 12 2019
Publicly Disclosed Yes
CISA KEV Not Listed
Known Exploits None Known

EPSS Score

No EPSS score available for this CVE.

View on FIRST.org

Affected Products

4 affected products
Product KB Article Severity Impact Restart Required
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 26 4487052 (Security Update) Unknown Elevation of Privilege Maybe
Microsoft Exchange Server 2013 Cumulative Update 22 4345836 (Security Update) Unknown Elevation of Privilege Maybe
Microsoft Exchange Server 2016 Cumulative Update 12 4471392 (Security Update) Unknown Elevation of Privilege Maybe
Microsoft Exchange Server 2019 Cumulative Update 1 4471391 (Security Update) Unknown Elevation of Privilege Maybe

Patches

4 patches
Article Type Restart
4487052 Security Update Maybe
4345836 Security Update Maybe
4471392 Security Update Maybe
4471391 Security Update Maybe

Known Exploits

Acknowledgments

Microsoft has not published researcher acknowledgments for this CVE, or they are not yet reflected in our data source. Check the MSRC advisory directly for the most current credit information.