CVE-2020-17132

CRITICAL

Microsoft Exchange - RCE

Title source: llm

Description

Microsoft Exchange Remote Code Execution Vulnerability

Exploits (1)

metasploit WORKING POC EXCELLENT
by Leonard Rapp, Markus Vervier, Steven Seeley, Yasar Klawohn, wvu, Spencer McIntyre · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/exchange_ecp_dlp_policy.rb

Scores

CVSS v3 9.1
EPSS 0.8288
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Details

Status published
Products (3)
microsoft/exchange_server 2013 cumulative_update_23
microsoft/exchange_server 2016 cumulative_update_17 (2 CPE variants)
microsoft/exchange_server 2019 cumulative_update_6 (2 CPE variants)
Published Dec 10, 2020
Tracked Since Feb 18, 2026