PT-2020-4017 · Microsoft · Exchange Server

Mr_Me

+1

·

Published

2020-09-08

·

Updated

2023-12-31

·

CVE-2020-16875

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Exchange Server (affected versions not specified)
Description: A remote code execution issue exists in Microsoft Exchange server due to improper validation of cmdlet arguments. This could allow an attacker to run arbitrary code in the context of the System user. Exploitation requires an authenticated user in a certain Exchange role to be compromised. The issue is related to errors in handling objects in memory.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Special Elements Injection

Improper Privilege Management

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2020-04417
CVE-2020-16875

Affected Products

Exchange Server