CVE-2020-16875
Summary
| CVE | CVE-2020-16875 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-11 17:15:00 UTC |
| Updated | 2023-12-31 22:15:00 UTC |
| Description | A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user, aka 'Microsoft Exchange Server Remote Code Execution Vulnerability'. |
Risk And Classification
Problem Types: CWE-74 | CWE-269
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_16 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_17 | All | All |
| Application | Microsoft | Exchange Server | 2019 | cumulative_update_5 | All | All |
| Application | Microsoft | Exchange Server | 2019 | cumulative_update_6 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_16 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_17 | All | All |
| Application | Microsoft | Exchange Server | 2019 | cumulative_update_5 | All | All |
| Application | Microsoft | Exchange Server | 2019 | cumulative_update_6 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Exchange Server DlpUtils AddTenantDlpPolicy Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| N/A | N/A | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.