webmaster@theregister.co.uk (Thomas Claburn) / The Register
Youre an admin! Youre an admin! Youre all admins, thanks to this Microsoft Exchange zero-day and – Easily swapped hashed passwords gives Domain Admin rights via API call. Fix may land next month Microsoft Exchange appears to be currently vulnerable to a privilege escalation attack that allows any user with a mailbox to become a Domain Admin. …