First published: Wed Dec 09 2020(Updated: )
Microsoft Exchange Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17132, CVE-2020-17141, CVE-2020-17142, CVE-2020-17144.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2013-cumulative_update_23 | |
Microsoft Exchange Server | =2016-cumulative_update_17 | |
Microsoft Exchange Server | =2016-cumulative_update_18 | |
Microsoft Exchange Server | =2019-cumulative_update_6 | |
Microsoft Exchange Server | =2019-cumulative_update_7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-17117 has been assigned a critical severity rating due to its potential to allow remote code execution.
To fix CVE-2020-17117, apply the latest security patches released by Microsoft for affected versions of Exchange Server.
CVE-2020-17117 affects Microsoft Exchange Server versions 2013 (Cumulative Update 23), 2016 (Cumulative Updates 17 and 18), and 2019 (Cumulative Updates 6 and 7).
CVE-2020-17117 is a remote code execution vulnerability that can be exploited by an unauthenticated attacker.
Yes, CVE-2020-17117 can be exploited remotely without user interaction, making it particularly dangerous.