cbcvebase.
CVE-2020-16875
published 2020-09-11

CVE-2020-16875: A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments. An attacker who successfully…

PriorityP181high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
ITWEXPLOITVulnCheck KEVRansomware
Exploited in the wild
EPSS
47.14%
98.7th percentile
A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the vulnerability requires an authenticated user in a certain Exchange role to be compromised. The security update addresses the vulnerability by correcting how Microsoft Exchange handles cmdlet arguments.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftexchange_server
microsoftexchange_server
microsoftmicrosoft_exchange_server_2016_cumulative_update_16>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_17>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_5>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_6>= 15.02.0 < publicationpublication
msrcmicrosoft_exchange_server_2010_service_pack_3
msrcmicrosoft_exchange_server_2013_cumulative_update_21
msrcmicrosoft_exchange_server_2013_cumulative_update_22
msrcmicrosoft_exchange_server_2013_cumulative_update_23
msrcmicrosoft_exchange_server_2013_service_pack_1
msrcmicrosoft_exchange_server_2016_cumulative_update_10
msrcmicrosoft_exchange_server_2016_cumulative_update_11
msrcmicrosoft_exchange_server_2016_cumulative_update_12
msrcmicrosoft_exchange_server_2016_cumulative_update_13
msrcmicrosoft_exchange_server_2016_cumulative_update_14
msrcmicrosoft_exchange_server_2016_cumulative_update_15
msrcmicrosoft_exchange_server_2016_cumulative_update_16
msrcmicrosoft_exchange_server_2016_cumulative_update_17
msrcmicrosoft_exchange_server_2016_cumulative_update_18
msrcmicrosoft_exchange_server_2016_cumulative_update_19
msrcmicrosoft_exchange_server_2016_cumulative_update_8
msrcmicrosoft_exchange_server_2016_cumulative_update_9
msrcmicrosoft_exchange_server_2019
msrcmicrosoft_exchange_server_2019_cumulative_update_1

Detection & IOCsextracted from sources · hover to see the quote

processNew-DlpPolicy
  • Exploitation requires an authenticated user with the 'Data Loss Prevention' role — monitor for Exchange ECP requests involving DLP policy creation (New-DlpPolicy) from unexpected or low-privilege accounts.
  • Exploitation results in code execution as SYSTEM on the Exchange server — alert on SYSTEM-level process spawning from Exchange worker processes (e.g., w3wp.exe spawning cmd.exe or powershell.exe).
  • Exploitation vector is HTTP against the Exchange ECP (Exchange Control Panel) endpoint — monitor for anomalous POST requests to ECP DLP policy management paths from authenticated users.
  • ·Exploitation requires the target account to have the 'Data Loss Prevention' role and an active mailbox — not all authenticated Exchange users are exploitable.
  • ·Affected versions confirmed as Exchange Server 2016 and 2019; Metasploit module was tested against Exchange Server 2016 CU19 on Windows Server 2016.

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vulncheck8.4HIGH
vendor_msrc9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.