ZeroHour

CVE-2020-17144

KEVmass1

Remote Code Execution in Microsoft Exchange Server via Cmdlet Argument Validation

CISA: Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 3.1
8.4 high
EPSS
37%p98
Published
()
KEV added
AI analysis

CVE-2020-17144 is a remote code execution vulnerability in Microsoft Exchange Server caused by improper validation of cmdlet arguments; the associated weakness class (CWE-502, deserialization of untrusted data) indicates that improperly validated attacker-supplied arguments are deserialized and executed by the server. An attacker triggers the flaw by sending specially crafted cmdlet arguments to a vulnerable Exchange server, causing attacker-controlled code to run on the server. Successful exploitation yields remote code execution on the Exchange host, which could provide command execution in the Exchange service context, access to mail data, and a foothold for further compromise. Organizations running affected on-premises Microsoft Exchange Server deployments are affected; the available data lists 'Microsoft Exchange Server' without specifying version ranges, and cloud-based Exchange Online is not implicated by this server-side flaw. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2021-11-03, EPSS is high at 36.5% (98th percentile), no public PoC is known, and any association with ransomware is unknown.

What to do: Inventory all on-premises Exchange servers and verify their current patch level, then apply Microsoft's Exchange security updates containing this fix (released in the November 2020 Patch Tuesday) per the CISA required action. Until patched, restrict access to Exchange management/cmdlet interfaces and review Exchange and PowerShell logs for unexpected cmdlet or deserialization activity. Given the confirmed in-the-wild exploitation (KEV) and elevated EPSS (36.5%), treat this as a high-priority patch even though no public PoC exists.

Affected
Microsoft Exchange Server
Estimated exposure
masshundreds of thousands of on-premises Exchange deployments worldwide — Exchange is one of the most widely deployed on-premises mail platforms, and public internet-scan estimates published during the 2021 Exchange exploitation waves counted roughly 250,000-500,000 internet-facing Exchange servers, with total…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Exchange Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Exchange Server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
exchange server
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

In the news