Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
What type of information could be disclosed by this vulnerability? Exploiting this vulnerability could allow the disclosure of credentials. According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation requires an attacker to first obtain a valid encrypted authentication cookie through a separate compromise and then make repeated requests to infer the protected credentials. These additional prerequisites make exploitation difficult and time-consuming.
Michael Maturi with <a href="https://google.com/">Google/Mandiant</a>