CVE-2020-17132: Microsoft Exchange Remote Code Execution Vulnerability
Published Dec 8, 2020
·Updated
Microsoft Exchange Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17117, CVE-2020-17141, CVE-2020-17142, CVE-2020-17144.
Affected Software
10 affected componentsFixes available
Microsoft Exchange Server=2013-cumulative_update_23
Microsoft Exchange Server=2016-cumulative_update_17
Microsoft Exchange Server=2016-cumulative_update_18
Microsoft Exchange Server=2019-cumulative_update_6
Microsoft Exchange Server=2019-cumulative_update_7
Microsoft Exchange Server 2019=7
Microsoft Exchange Server 2016=18
Microsoft Exchange Server 2013=23
Microsoft Exchange Server 2019=6
Microsoft Exchange Server 2016=17
Remediation
Event History
Dec 8, 2020
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Description
Dec 9, 2020
CVE Published
via MITRE·11:36 PM
Data Sourced
via MITRE·11:36 PM
DescriptionSeverity
Dec 10, 2020
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2020-17132?
CVE-2020-17132 is a Microsoft Exchange Remote Code Execution Vulnerability.
2
What is the severity of CVE-2020-17132?
CVE-2020-17132 has a severity rating of 9.1 (critical).
3
Which software versions are affected by CVE-2020-17132?
CVE-2020-17132 affects Microsoft Exchange Server 2013 cumulative update 23, 2016 cumulative update 17 and 18, and 2019 cumulative update 6 and 7.
4
How can I fix CVE-2020-17132?
To fix CVE-2020-17132, it is recommended to apply the relevant security updates provided by Microsoft.
5
Where can I find more information about CVE-2020-17132?
More information about CVE-2020-17132 can be found on the Microsoft Security Guidance Advisory page: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-17132