CVE-2019-0724
HIGHMicrosoft Exchange Privilege Escalation Exploit
Title source: metasploitExploitation Summary
EIP tracks 1 public exploit for CVE-2019-0724.
PoCs published by _dirkjan, Petros Koutroumpis, including Metasploit module auxiliary/scanner/http/exchange_web_server_pushsubscription.
AI-analyzed exploit summary This Metasploit module exploits CVE-2019-0724, a privilege escalation vulnerability in Microsoft Exchange, by forcing the server to authenticate to an attacker-controlled URL via the PushSubscription feature. It leverages NTLM relaying to escalate privileges to those of the Exchange server.
Description
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0686.
Exploits (1)
This Metasploit module exploits CVE-2019-0724, a privilege escalation vulnerability in Microsoft Exchange, by forcing the server to authenticate to an attacker-controlled URL via the PushSubscription feature. It leverages NTLM relaying to escalate privileges to those of the Exchange server.
References (2)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H