CVE-2020-16875

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
11/09/2020
Last modified:
31/12/2023

Description

A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.<br /> An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the vulnerability requires an authenticated user in a certain Exchange role to be compromised.<br /> The security update addresses the vulnerability by correcting how Microsoft Exchange handles cmdlet arguments.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_16:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_17:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_5:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_6:*:*:*:*:*:*