[German]Since February 13, 2024, a vulnerability CVE-2024-21410 has been known, through which attackers can access NTLM hashes via Microsoft Exchange Server and then misuse them for NTLM relay or pass-the-hash attacks. I have now read that more than 28,500 Exchange servers are vulnerable via CVE-2024-21410. Administrators must therefore take action and secure their IT infrastructure. In this context, I also came across an analysis by Frank Carius, who sees the vulnerability not in the Exchange Server but in the IIS. So there is potentially much more affected.
Translate
Blogs
Links
Social networks
Awards
Sponsors
(Paypal-Donations)
[
[
[
[
Zyxel has released a security patch "ZLD5.37 Patch2" for its ZyWALL ATP, ZyWALL USG FLEX and ZyWALL VPN solutions on February 20, 2024, which closes the vulnerabilities 

