KLA11664
Multiple vulnerabilities in Microsoft Exchange Server
Обновлено: 13/03/2020
Дата обнаружения
11/02/2020
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Microsoft Exchange Server. Malicious users can exploit these vulnerabilities to gain privileges, execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. An elevation of privilege vulnerability in Microsoft Exchange Server can be exploited remotely to gain privileges.
  2. A memory corruption vulnerability in Microsoft Exchange can be exploited remotely via specially crafted email to execute arbitrary code.
Пораженные продукты

Microsoft Exchange Server 2016 Cumulative Update 14
Microsoft Exchange Server 2016 Cumulative Update 15
Microsoft Exchange Server 2013 Cumulative Update 23
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 30
Microsoft Exchange Server 2019 Cumulative Update 4
Microsoft Exchange Server 2019 Cumulative Update 3

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2020-0692
CVE-2020-0688
Оказываемое влияние
?
ACE 
[?]

PE 
[?]
Связанные продукты
Microsoft Exchange Server
CVE-IDS
CVE-2020-06920.0Unknown
CVE-2020-06880.0Unknown
KB list

4536988
4536989
4536987

Microsoft official advisories
Microsoft Security Update Guide