Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2020-16875 | First vendor Publication | 2020-09-11 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:S/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 8 | Authentication | Requires single instance |
Calculate full CVSS 2.0 Vectors scores |
Detail
A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the vulnerability requires an authenticated user in a certain Exchange role to be compromised. The security update addresses the vulnerability by correcting how Microsoft Exchange handles cmdlet arguments. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16875 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
50 % | CWE-269 | Improper Privilege Management |
50 % | CWE-74 | Failure to Sanitize Data into a Different Plane ('Injection') |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 4 |
Snort® IPS/IDS
Date | Description |
---|---|
2020-10-27 | Microsoft Exchange Server DlpUtils remote code execution attempt RuleID : 55826 - Revision : 1 - Type : SERVER-WEBAPP |
Metasploit Database
id | Description |
---|---|
2020-09-08 | Microsoft Exchange Server DlpUtils AddTenantDlpPolicy RCE |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2024-11-28 13:40:53 |
|
2024-01-01 00:27:40 |
|
2022-04-29 02:04:44 |
|
2021-08-05 01:37:39 |
|
2021-07-21 17:23:27 |
|
2021-05-04 13:49:59 |
|
2021-04-22 03:01:42 |
|
2020-10-27 21:23:17 |
|
2020-09-17 21:23:16 |
|
2020-09-17 17:24:32 |
|
2020-09-17 00:22:42 |
|
2020-09-11 21:23:10 |
|