Blog

"Proxy Token" vulnerability in Exchange Server, fear of email eavesdropping

ZDNet Japan Staff

2021-08-31 10:19

  • Here's my content

  • The Zero Day Initiative (ZDI), a subsidiary of Trend Micro, released information on a vulnerability (CVE-2021-33766) related to Microsoft Exchange Server named "Proxy Token" on August 30th. The email may be eavesdropped. The patch was released in a security update in July, encouraging users to apply it.

    According to ZDI, this vulnerability is related to the system configuration of Exchange Server. Exchange Server consists of a front end that receives access to Exchange Server mail from external clients through Outlook Web Access (OWA), etc., and an "Exchange back end".

    The front end acts as a proxy to the Exchange back end. Since most Exchange services require authentication, the frontend sends the credentials entered in the web form to the Exchange backend, and when the Exchange backend processes it, it responds to the frontend. .. Among these authentication methods, there is a function called "Delegated Authentication" in which the front end directly passes the authentication request to the Exchange back end side.

    The vulnerability is attributed to this mandate authentication. In delegation authentication, when the frontend finds a cookie containing a security token, it delegates authentication to the Exchange backend side. However, the default configuration prevents the Exchange backend from loading modules that perform delegation authentication, and in some cases it does not recognize authentication requests by cookies containing security tokens.

    Eventually, the authentication request will pass without going through the appropriate authentication process, and the attacker can change the reception settings of any user and forward the mail to the attacker. ..

    Exchange Serverに「ProxyToken」の脆弱性、メール盗聴の恐れ

    The vulnerability was reported to ZDI by Vietnamese security researcher Le Xuan Tuyen, and Microsoft released a patch in a security update in July. However, although the patch itself was developed by April and preparations for release were in progress, it was delayed due to a mistake.

    Read all ZDNet Japan articles by email every morning (free registration)

    Apply for e-mail newsletter subscription

    Related article

    Related keywords
    Vulnerability

    Related white paper

    Popular category
    management
    Security
    Cloud computing
    Virtualization
    Business application
    mobile

    Hot Articles

    How to Save Websites as PDF on iPhone or PC | Business Insider Japan

    How to Save Websites as PDF on iPhone or PC | Business Insider Japan

    Sign up for a free e-mail newsletter We'll send you a Business Insider Japan e-mail newsletter at 17:00 on weekdays. Check the terms of use You can save the website as a PDF from various web browsers including Safari on iPhone. Photo: Takuma Imamura Web page suddenly ...

    READ MORE READ MORE
    Yahoo! News Digitalizing the traditional "small pattern dyeing" pattern Crisis of disappearance, challenge of long-established president

    Yahoo! News Digitalizing the traditional "small pattern dyeing" pattern Crisis of disappearance, challenge of long-established president

    In the file in front of Mr. Atsushi Tomita, a well-preserved paper pattern is included so that it is not exposed to the air as much as possible. To prepare for digitization and prevent deterioration = Taken by Hiroyuki Kondo on the morning of December 10, 2021 at Tomita Dyeing Crafts in Shinjuku-ku, Tokyo ...

    READ MORE READ MORE
     It's okay if you forget to record the news!How to see the famous scenes of the Olympics later on your smartphone

    It's okay if you forget to record the news!How to see the famous scenes of the Olympics later on your smartphone

    Explaining how to use the archive distribution The Tokyo Olympics attracts attention not only for players' play but also for unique commentary. Even if you miss it even though it became a hot topic, or if you did not record it, you can do it at your favorite timing later ...

    READ MORE READ MORE

    Related Articles