PT-2020-4017 · Microsoft · Exchange Server
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Exchange server (affected versions not specified)
Description
A remote code execution issue exists due to improper validation of cmdlet arguments. An attacker could exploit this to run arbitrary code in the context of the System user. Successful exploitation requires the compromise of an authenticated user assigned to a specific Exchange role.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
RCE
Code Injection
Special Elements Injection
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Exchange Server