Skip to content

Added Exchange Web Services PushSubscription CVE-2019-0724 auxiliary module #11420

Merged
dwelch-r7 merged 19 commits intorapid7:masterfrom
pkb1s:exchange_web_server_pushsubscription
Oct 18, 2019
Merged

Added Exchange Web Services PushSubscription CVE-2019-0724 auxiliary module #11420
dwelch-r7 merged 19 commits intorapid7:masterfrom
pkb1s:exchange_web_server_pushsubscription

Conversation

@pkb1s
Copy link
Contributor

@pkb1s pkb1s commented Feb 16, 2019

Execution of the module will force Exchange to authenticate to an specified URL over HTTP via the Exchange PushSubscription feature. This allows us to relay the NTLM authentication to a Domain Controller and authenticate with the privileges that Exchange is configured.

@pkb1s pkb1s changed the title Added Exchange Web Server PushSubscription CVE-2019-0686 auxiliary module Added Exchange Web Services PushSubscription CVE-2019-0686 auxiliary module Feb 17, 2019
@pkb1s pkb1s changed the title Added Exchange Web Services PushSubscription CVE-2019-0686 auxiliary module Added Exchange Web Services PushSubscription CVE-2019-0724 auxiliary module Feb 17, 2019
@acammack-r7 acammack-r7 self-assigned this Mar 5, 2019
@pkb1s
Copy link
Contributor Author

pkb1s commented Apr 11, 2019

Hello! Does this PR wait for an action from me or is it just that there is a big backlog and you haven't had the time to look into it?

@dwelch-r7 dwelch-r7 self-assigned this Oct 8, 2019
@dwelch-r7 dwelch-r7 merged commit 8eed4c7 into rapid7:master Oct 18, 2019
@dwelch-r7
Copy link
Contributor

dwelch-r7 commented Oct 19, 2019

Release notes

This adds an auxiliary module to CVE-2019-0724 that can used to make a request to a Microsoft Exchange server and force it to authenticate to a URL under your control.

@tperry-r7 tperry-r7 added rn-modules release notes for new or majorly enhanced modules rn-enhancement release notes enhancement and removed rn-modules release notes for new or majorly enhanced modules labels Oct 30, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docs module rn-enhancement release notes enhancement

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants