HIGH
CVE-2020-17144
CVSS
8.4
KEV
Description
Microsoft Exchange Remote Code Execution Vulnerability
Summary dbcve.org
This is a remote code execution vulnerability in Microsoft Exchange Server that allows an authenticated attacker to execute arbitrary code on the target system. The vulnerability has a CVSS score of 8.4 (HIGH) and is network-exploitable with low attack complexity.
Mitigation
Apply the Microsoft security update for CVE-2020-17144 to affected Microsoft Exchange Server installations. If immediate patching is not possible, restrict network access to Exchange servers and monitor for indicators of compromise.
Weakness (CWE)
CWE-502
Deserialization of Untrusted Data
EPSS Score
36.51%
Probability of exploitation in next 30 days
98.4th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-17144
Patch, Vendor Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-17144
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-17144
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.