CVE-2020-17132

CWE-94Code Injection6 documents6 sources
Severity
9.1CRITICAL
EPSS
82.8%
top 0.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10
Latest updateMay 24

Description

Microsoft Exchange Remote Code Execution Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 2.3 | Impact: 6.0

Affected Packages6 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-vqv9-x245-gqwv: , aka 'Microsoft Exchange Remote Code Execution Vulnerability'2022-05-24
CVEList
Microsoft Exchange Remote Code Execution Vulnerability2020-12-09
Project0
Project Zero RCA: CVE-2021-26855: Microsoft Exchange Server-Side Request Forgery

🔍Detection Rules

1
Suricata
ET EXPLOIT Microsoft Exchange Server Exploitation Inbound (CVE-2020-17132)2021-01-08

📋Vendor Advisories

1
Microsoft
Microsoft Exchange Remote Code Execution Vulnerability2020-12-08
CVE-2020-17132 (CRITICAL CVSS 9.1) | Microsoft Exchange Remote Code Exec | cvebase.io