Security News > 2021 > August > Microsoft Exchange ProxyToken bug can let hackers steal user email

Technical details have emerged on a serious vulnerability in Microsoft Exchange Server dubbed ProxyToken that does not require authentication to access emails from a target account.
An attacker can exploit the vulnerability by crafting a request to web services within the Exchange Control Panel application and steal messages from a victim's inbox.
Tracked as CVE-2021-33766, ProxyToken gives unauthenticated attackers access to the configuration options of user mailboxes, where they can define an email forwarding rule.
In Microsoft Exchange deployments where the "Delegated Authentication" feature is active, the frontend forwards the requests that need authentication to the backend, which identifies them by the presence of a 'SecurityToken' cookie.
The default configuration of Microsoft Exchange does not load for the backend ECP site the module responsible for delegating the validation process.
As in the case of ProxyShell vulnerabilities, if administrators of Microsoft Exchange servers have not installed the patches for ProxyToken, they should prioritize the task.
News URL
Related news
- Microsoft: Hackers steal emails in device code phishing attacks (source)
- Microsoft: Exchange Online bug mistakenly quarantines user emails (source)
- Microsoft: Russian-Linked Hackers Using 'Device Code Phishing' to Hijack Accounts (source)
- Chinese hackers abuse Microsoft APP-v tool to evade antivirus (source)
- Microsoft's End of Support for Exchange 2016 and 2019: What IT Teams Must Do Now (source)
- Suspected Iranian Hackers Used Compromised Indian Firm's Email to Target U.A.E. Aviation Sector (source)
- Microsoft: North Korean hackers join Qilin ransomware gang (source)
- Microsoft Warns of ClickFix Phishing Campaign Targeting Hospitality Sector via Fake Booking[.]com Emails (source)
- Week-long Exchange Online outage causes email failures, delays (source)
- Microsoft Exchange Online outage affects Outlook web users (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-07-14 | CVE-2021-33766 | Unspecified vulnerability in Microsoft Exchange Server 2013/2016/2019 Microsoft Exchange Server Information Disclosure Vulnerability | 0.0 |