First published: Wed Dec 09 2020(Updated: )
Microsoft Exchange Information Disclosure Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2013-cumulative_update_23 | |
Microsoft Exchange Server | =2016-cumulative_update_17 | |
Microsoft Exchange Server | =2016-cumulative_update_18 | |
Microsoft Exchange Server | =2019-cumulative_update_6 | |
Microsoft Exchange Server | =2019-cumulative_update_7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-17143 is a vulnerability in Microsoft Exchange Server that allows attackers to disclose sensitive information.
The severity of CVE-2020-17143 is high with a CVSS score of 8.8.
Microsoft Exchange Server 2013 (Cumulative Update 23), Exchange Server 2016 (Cumulative Update 17 and 18), and Exchange Server 2019 (Cumulative Update 6 and 7) are affected by CVE-2020-17143.
Attackers can exploit CVE-2020-17143 by sending specially crafted requests to a vulnerable Microsoft Exchange server and gaining access to sensitive information.
Yes, Microsoft has released security updates to address the vulnerability. It is recommended to apply the latest cumulative updates for the affected versions of Microsoft Exchange Server.