Microsoft Exchange ProxyToken Bug May Allow Email User Theft

Share post:

The details of a Microsoft Exchange Server vulnerability that allows hackers to steal email information have been disclosed.

The vulnerability – “ProxyToken” – allows hackers to send emails without authentication. Instead, the attacker makes a request to web services within the Exchange Control Panel application to gain access to messages from the victim’s inbox.

With this exploit, hackers could also forward messages intended for a target user to an account they control.

The bug was discovered and publicized last March by a researcher at the Information Security Center of Vietnam Posts and Telecommunications Group.

Since its discovery, Microsoft has announced a patch that has been available since July. The tech giant says the vulnerability is not critical, while the National Institute of Standards and Technology puts its severity score at 7.5 out of 10 because an attacker needs an account on the same Exchange server as the victim.

For more information, view the original story from Bleeping Computer.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Controversial expansion of US surveillance powers nears Senate vote

The US Senate is poised to vote on a significant expansion of Section 702 of the Foreign Intelligence...

Russian-linked hackers target U.S. and European water systems

A Russian military-affiliated hacking group, Sandworm, is suspected of coordinating recent cyberattacks on water utilities in the U.S.,...

Cisco Duo’s Multifactor Authentication service compromised by social engineering attack

Cisco Duo, a prominent provider of multifactor authentication (MFA) services, has fallen victim to a cyberattack targeting one...

Cyber Security Today, April 17, 2024 – More suspicious attempts to take over open source projects, a data theft at a Cisco Duo partner,...

This episode reports on security updates from Delinea and PuTTY, and reports on bad bots and threat actors going after Zoo

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways