packetstormsecurity.com
http://packetstormsecurity.com/files/159210/Microsoft-Exchange-Server-DlpUtils-AddTenantDlpPolicy-Remote-Code-Execution.html CVE-2020-16875
HIGHRansomware
Microsoft Exchange Server Remote Code Execution Vulnerability
Record summary
CVE-2020-16875 has a selected CVSS score of 8.4 (high); EIP currently links 1 catalogued exploit. VulnCheck reports CVE-2020-16875 use in known ransomware campaigns.
Description
A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user, aka 'Microsoft Exchange Server Remote Code Execution Vulnerability'.
Description source: GitHub Advisory
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 21, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
Exchange ServerBrowse Microsoft / Exchange Server | VulnCheck | Version data not supplied | |
Microsoft Exchange Server 2016 Cumulative Update 16Browse Microsoft / Microsoft Exchange Server 2016 Cumulative Update 16 | CVE List | 15.01.0 to < publication | affected |
Microsoft Exchange Server 2016 Cumulative Update 17Browse Microsoft / Microsoft Exchange Server 2016 Cumulative Update 17 | CVE List | 15.01.0 to < publication | affected |
Microsoft Exchange Server 2019 Cumulative Update 5Browse Microsoft / Microsoft Exchange Server 2019 Cumulative Update 5 | CVE List | 15.02.0 to < publication | affected |
Microsoft Exchange Server 2019 Cumulative Update 6Browse Microsoft / Microsoft Exchange Server 2019 Cumulative Update 6 | CVE List | 15.02.0 to < publication | affected |
Proofs of concept
1Catalogued exploits
MetasploitMicrosoft Exchange Server DlpUtils AddTenantDlpPolicy RCEMetasploit exploitby Leonard Rapp +5 moreNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-16875 portal.msrc.microsoft.com
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16875