cbcvebase.
CVE-2020-17143
published 2020-12-10

CVE-2020-17143: Microsoft Exchange Server Information Disclosure Vulnerability

PriorityP263high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
70.63%
99.3th percentile
Microsoft Exchange Server Information Disclosure Vulnerability

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftexchange_server
microsoftexchange_server
microsoftexchange_server
microsoftmicrosoft_exchange_server_2013_cumulative_update_23>= 15.00.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_17>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2016_cumulative_update_18>= 15.01.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_6>= 15.02.0 < publicationpublication
microsoftmicrosoft_exchange_server_2019_cumulative_update_7>= 15.02.0 < publicationpublication
msrcmicrosoft_exchange_server_2010_service_pack_3
msrcmicrosoft_exchange_server_2013_cumulative_update_21
msrcmicrosoft_exchange_server_2013_cumulative_update_22
msrcmicrosoft_exchange_server_2013_cumulative_update_23
msrcmicrosoft_exchange_server_2013_service_pack_1
msrcmicrosoft_exchange_server_2016_cumulative_update_10
msrcmicrosoft_exchange_server_2016_cumulative_update_11
msrcmicrosoft_exchange_server_2016_cumulative_update_12
msrcmicrosoft_exchange_server_2016_cumulative_update_13
msrcmicrosoft_exchange_server_2016_cumulative_update_14
msrcmicrosoft_exchange_server_2016_cumulative_update_15
msrcmicrosoft_exchange_server_2016_cumulative_update_16
msrcmicrosoft_exchange_server_2016_cumulative_update_17
msrcmicrosoft_exchange_server_2016_cumulative_update_18
msrcmicrosoft_exchange_server_2016_cumulative_update_19
msrcmicrosoft_exchange_server_2016_cumulative_update_8
msrcmicrosoft_exchange_server_2016_cumulative_update_9

Detection & IOCsextracted from sources · hover to see the quote

url/owa/service.svc
otheraction: GetWacIframeUrlForOneDrive
other"EndPointUrl":"
snort
alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Microsoft Exchange Server OWA GetWacUrl Information Disclosure Attempt (CVE-2020-17143)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/owa/service.svc"; fast_pattern; http.request_header; header_lowercase; content:"action|3a 20|GetWacIframeUrlForOneDrive"; startswith; nocase; http.request_header; content:"|22|EndPointUrl|22 3a 22|"; nocase; reference:cve,2020-17143; classtype:web-application-attack; sid:2035138; rev:3; metadata:attack_target Server, created_at 2022_02_08, cve CVE_2020_17143, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, updated_at 2024_04_25, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
  • Exploit traffic is an HTTP POST request directed to the Exchange OWA service endpoint /owa/service.svc
  • The HTTP request header contains the SOAP/service action 'GetWacIframeUrlForOneDrive' (case-insensitive, at the start of the header value), indicating abuse of the GetWacUrl functionality
  • The request body/header also contains the JSON key 'EndPointUrl' with a value, which is the parameter being manipulated to trigger information disclosure
  • Traffic should be inspected on the perimeter and internally (both deployment contexts flagged), targeting Exchange Server hosts
  • MITRE ATT&CK mapping: Tactic TA0001 (Initial Access), Technique T1190 (Exploit Public-Facing Application)
  • ·The Snort/Suricata rule targets $HOME_NET and $HTTP_SERVERS — ensure these variables are correctly scoped to include Exchange Server IPs/subnets for accurate detection coverage
  • ·Rule confidence is rated Medium by the ET ruleset authors; tune accordingly to reduce false positives in environments with legitimate OWA/OneDrive integrations using GetWacIframeUrlForOneDrive

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.