PT-2020-4017 · Microsoft · Exchange Server
Mr_Me
+1
·
Published
2020-09-08
·
Updated
2023-12-31
·
CVE-2020-16875
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Microsoft Exchange Server (affected versions not specified)
Description:
A remote code execution issue exists in Microsoft Exchange server due to improper validation of cmdlet arguments. This could allow an attacker to run arbitrary code in the context of the System user. Exploitation requires an authenticated user in a certain Exchange role to be compromised. The issue is related to errors in handling objects in memory.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Special Elements Injection
Improper Privilege Management
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Exchange Server