KLA12000
Multiple vulnerabilities in Microsoft Exchange Server

Обновлено: 16/11/2020
Дата обнаружения
10/11/2020
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Microsoft Echange Server. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerabilty Microsoft Exchange Server can be exploited remotely to execute arbitrary code.
  2. A denial of service vulnerabilty Microsoft Exchange Server can be exploited to cause denial of service.
Пораженные продукты

Microsoft Exchange Server 2019 Cumulative Update 7
Microsoft Exchange Server 2016 Cumulative Update 17
Microsoft Exchange Server 2019 Cumulative Update 6
Microsoft Exchange Server 2013 Cumulative Update 23
Microsoft Exchange Server 2016 Cumulative Update 18

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2020-17083
CVE-2020-17084
CVE-2020-17085
Оказываемое влияние
?
ACE 
[?]

DoS 
[?]
Связанные продукты
Microsoft Exchange Server
CVE-IDS
CVE-2020-170833.5Warning
CVE-2020-170849.0Critical
CVE-2020-170854.0Warning
KB list

4588741