Exploit/Advisories no image

Published on April 20th, 2022 📆 | 3485 Views ⚑

0

Microsoft Exchange Active Directory Topology 15.0.847.40 Unquoted Service Path – Torchsec


iSpeech

Microsoft Exchange Active Directory Topology 15.0.847.40 Unquoted Service Path
Posted Apr 18, 2022
Authored by Antonio Cuomo

Microsoft Exchange Active Directory Topology version 15.0.847.40 suffers from an unquoted service path vulnerability.

tags | exploit
MD5 | 6d6971d6126021087c4c104a434eb452
# Exploit Title: Microsoft Exchange Active Directory Topology 15.0.847.40 - 'Service MSExchangeADTopology' Unquoted Service Path
# Exploit Author: Antonio Cuomo (arkantolo)
# Exploit Date: 2022-04-11
# Vendor : Microsoft
# Version : 15.0.847.40
# Tested on OS: Microsoft Exchange Server 2013 SP1

#PoC :
==============

C:>sc qc MSExchangeADTopology
[SC] QueryServiceConfig OPERAZIONI RIUSCITE





NOME_SERVIZIO: MSExchangeADTopology
TIPO : 10 WIN32_OWN_PROCESS
TIPO_AVVIO : 2 AUTO_START
CONTROLLO_ERRORE : 1 NORMAL
NOME_PERCORSO_BINARIO : C:Program FilesMicrosoftExchange ServerV15BinMicrosoft.Exchange.Directory.TopologyService.exe
GRUPPO_ORDINE_CARICAMENTO :
TAG : 0
NOME_VISUALIZZATO : Microsoft Exchange Active Directory Topology
DIPENDENZE :
SERVICE_START_NAME : LocalSystem

Source link

Tagged with:



Comments are closed.