Security News > 2023 > November > New Microsoft Exchange zero-days allow RCE, data theft attacks

New Microsoft Exchange zero-days allow RCE, data theft attacks
2023-11-03 15:14

Microsoft Exchange is impacted by four zero-day vulnerabilities that attackers can exploit remotely to execute arbitrary code or disclose sensitive information on affected installations.

ZDI-23-1578 - A remote code execution flaw in the 'ChainedSerializationBinder' class, where user data isn't adequately validated, allowing attackers to deserialize untrusted data.

Attackers can exploit it to access sensitive information from Exchange servers.

Millions of Exim mail servers exposed to zero-day RCE attacks.

3,000 Apache ActiveMQ servers vulnerable to RCE attacks exposed online.

HelloKitty ransomware now exploiting Apache ActiveMQ flaw in attacks.


News URL

https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 365 50 1369 2819 161 4399