CVE-2020-17143: Microsoft Exchange Server Information Disclosure Vulnerability
Microsoft Exchange Information Disclosure Vulnerability
Other sources
Microsoft Exchange Server Information Disclosure Vulnerability
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-17143?
CVE-2020-17143 is a vulnerability in Microsoft Exchange Server that allows attackers to disclose sensitive information.
What is the severity of CVE-2020-17143?
The severity of CVE-2020-17143 is high with a CVSS score of 8.8.
Which versions of Microsoft Exchange Server are affected by CVE-2020-17143?
Microsoft Exchange Server 2013 (Cumulative Update 23), Exchange Server 2016 (Cumulative Update 17 and 18), and Exchange Server 2019 (Cumulative Update 6 and 7) are affected by CVE-2020-17143.
How can attackers exploit CVE-2020-17143?
Attackers can exploit CVE-2020-17143 by sending specially crafted requests to a vulnerable Microsoft Exchange server and gaining access to sensitive information.
Is there a fix available for CVE-2020-17143?
Yes, Microsoft has released security updates to address the vulnerability. It is recommended to apply the latest cumulative updates for the affected versions of Microsoft Exchange Server.