HIGH

CVE-2020-17144

Microsoft Exchange Server 2020-12-10 CVSS v3.1
CVSS
8.4
KEV

Description

Microsoft Exchange Remote Code Execution Vulnerability

Summary dbcve.org

This is a remote code execution vulnerability in Microsoft Exchange Server that allows an authenticated attacker to execute arbitrary code on the target system. The vulnerability has a CVSS score of 8.4 (HIGH) and is network-exploitable with low attack complexity.

Mitigation

Apply the Microsoft security update for CVE-2020-17144 to affected Microsoft Exchange Server installations. If immediate patching is not possible, restrict network access to Exchange servers and monitor for indicators of compromise.

Patch Commit

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

36.51%
Probability of exploitation in next 30 days
98.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE