Tagged: Exchange
4 posts · browse all tags
-
CVE-2026-45504 Part 1: Why On-Prem Exchange Is an Active Directory Attack Surface
On-prem Exchange has always been a heavily-trusted AD citizen, not a bolt-on app server. This series scopes a real, patched CVE against that history, and against a credential this blog already spent two other series getting a working password for.
-
CVE-2026-45504 Part 2: Inside the WOPI SSRF and Arbitrary File Read
A technical walkthrough of what CVE-2026-45504 actually does: a missing scheme check on an EWS ReferenceAttachment's provider URL, cited to Microsoft's advisory and HawkTrace's published research rather than reproduced as working exploit code.
-
CVE-2026-45504 Part 3: Why One Mailbox Credential Is Enough
svc-legacy-scan's cracked password has already powered two other series on this blog. CVE-2026-45504 shows what the same credential is worth against Exchange, with no ACL abuse and no privilege check required.
-
CVE-2026-45504 Part 4: Detection, Hardening, and Patching Priority
Patch first. After that, EWS activity logging and outbound-traffic baselining are the two layers that catch this kind of abuse, closing the loop this series opened with a six-year-old cracked password.