DEVCORE disclosed ProxyRelay, an attack surface in Microsoft Exchange Server that can coerce one Exchange server to authenticate over NTLM and relay its machine-account credentials to another Exchange service. Because Exchange machine accounts commonly possess the ms-Exch-EPI-Token-Serialization extended right, a successful relay can enable Exchange-user impersonation, mailbox access, authentication bypass, and, in certain attack chains, remote code execution.
The research covered Exchange Frontend and Backend services, Windows DCOM, and other NTLM-enabled endpoints, including issues tracked as CVE-2021-33768, CVE-2022-21979, CVE-2021-26414, and CVE-2022-24477. Microsoft issued fixes during 2021 and 2022; organizations needed to ensure relevant mitigations were activated, including IIS Extended Protection Authentication for Exchange Backend relay protection and DCOM hardening, which Microsoft enabled by default in June 2022. The disclosure illustrates the kind of high-impact enterprise exploitation research highlighted by the Zero Day Initiative's Pwn2Own Vancouver contest.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Microsoft published the CVEs and documentation explaining how to activate the applicable Exchange relay protections.
Microsoft addressed CVE-2022-21979 by forcibly enabling IIS Extended Protection Authentication, eliminating relay attacks against the Exchange Backend. Backend relay could otherwise target EWS, Outlook Anywhere RPC, or Exchange PowerShell services.
Microsoft enabled DCOM hardening by default during the second rollout phase, protecting Exchange servers with current Windows updates from the CVE-2021-26414 relay chain.
Microsoft released Exchange Server 2019 CU12 and Exchange Server 2016 CU23 with relevant architectural code changes. DEVCORE found its exploit still worked because the new protections were not enabled by default.
Microsoft released a fix for CVE-2021-33768 by preventing machine-account logons in the Exchange Frontend proxy handler. Successful relays to the Frontend EWS endpoint could otherwise enable user impersonation and mailbox operations.
DEVCORE reported an Exchange Server NTLM-relay attack surface to the Microsoft Security Response Center. The technique coerces an Exchange server to authenticate to an attacker-controlled host, enabling relay of its machine-account authentication to another Exchange server.
Microsoft patched the Windows DCOM relay issue tracked as CVE-2021-26414. The server-side DCOM hardening initially required administrators to manually activate it using the RequireIntegrityActivationAuthenticationLevel registry value.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.