Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
What privileges could be gained by an attacker who successfully exploited the vulnerability? The attacker would be able to take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments. How could an attacker exploit this vulnerability? An attacker authenticated to an affected Exchange server as a member of a highly privileged role group could send a specially crafted request over the network to bypass mailbox authorization checks. Successful exploitation could allow the attacker to access or modify another user's mailbox content without user interaction.
Bui Xuan Quang (buxu) with Ncsgroup.vn, Anonymous