cnotin (14)
Last Login: December 10, 2020
cnotin's Latest (4) Contributions
Technical Analysis
Require access to OWA EWS, authenticated with password or NTLM hash
Deserialization bug
Only concerns Exchange 2010 because the vulnerable feature is missing from later versions according to writeup
Technical Analysis
Exploit steps were published by SSD Advisory (files are mentioned but no download seems available). Instructions are precise enough to re-create it.
Local privilege escalation from unprivileged user to SYSTEM
Technical Analysis
CVSS 10 according to vendor
Technical details shared by Guardicore : from unauthenticated to admin (via LDAP). Implemented in a public exploit
MSF module to come.
That’s collaboration @wvu-r7 🙌