Emergency Exchange fix protects mailboxes from privilege abuse

Emergency Exchange fix protects mailboxes from privilege abuse. Organizations running Exchange on premises need an out-of-band security update for a high-severity authorization weakness.

Daily Cyber News: Emergency Exchange fix protects mailboxes from privilege abuse

Organizations running Exchange on premises need an out-of-band security update for a high-severity authorization weakness. An attacker must already have authenticated access, but successful exploitation could let that account reach other users’ mailboxes within the same organization and read messages and attachments. The issue doesn’t permit access across tenant boundaries.

Key context: A compromised account could therefore become a route to sensitive executive, legal or operational communications.

Additional detail: The larger lesson is that valid credentials become much more dangerous when authorization controls fail.

For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.

Topics: cybersecurity news, cybersecurity, cyber risk, Emergency Exchange, Emergency, Exchange, protects, mailboxes, privilege, abuse.

Emergency Exchange fix protects mailboxes from privilege abuse
Broadcast by