← back
CVE-2020-17144

Microsoft Exchange Remote Code Execution Vulnerability

CVSS 8.4 HIGHEPSS 36.5%● KEVCWE-502
In short

Microsoft Exchange has a vulnerability that allows attackers to execute malicious code remotely on affected servers. An attacker can exploit this flaw to take full control of the email system and access sensitive data.

Technical detail

This vulnerability involves unsafe deserialization of untrusted data in Microsoft Exchange, allowing remote code execution without authentication. An attacker can send specially crafted requests to trigger arbitrary code execution with SYSTEM privileges, leading to complete server compromise.

Summary generated and translated by AI from the official description.
Microsoft Exchange Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →