Description Preview
CVE-2020-17144 is a critical remote code execution vulnerability in Microsoft Exchange Server. The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data) and allows attackers to execute arbitrary code on affected systems by exploiting the server's improper handling of serialized objects. This vulnerability affects multiple versions of Microsoft Exchange Server and could lead to complete system compromise if successfully exploited.
Overview
This vulnerability exists in Microsoft Exchange Server due to improper validation of serialized data. An attacker who successfully exploits this vulnerability could run arbitrary code with SYSTEM privileges, allowing them to install programs, view, change, or delete data, or create new accounts with full user rights. The attack requires the attacker to send specially crafted data to an affected Exchange server. The vulnerability is particularly dangerous as it can potentially be exploited remotely without user interaction, making it a high priority for patching.
Remediation
To mitigate this vulnerability, administrators should:
- Apply the security update provided by Microsoft as soon as possible
- Ensure all Exchange servers are updated to the latest supported cumulative update and security update
- If immediate patching is not possible, consider implementing network segmentation and restricting access to Exchange servers
- Monitor Exchange server logs for suspicious activities
- Consider implementing additional security measures such as network-level authentication and proper network segmentation
- Follow Microsoft's security best practices for Exchange Server deployments
References
- Microsoft Security Advisory: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-17144
- Microsoft Security Response Center: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-17144
- Common Weakness Enumeration (CWE-502): https://cwe.mitre.org/data/definitions/502.html
- MITRE CVE Record: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17144
Early Warning
Armis Early Warning customers received an advanced alert on this vulnerability.
- Armis Alert Date
- Dec 16, 2020
- CISA KEV Date
- Nov 3, 2021
322days early
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- ManufacturingManufacturing
- Transportation & WarehousingTransportation & Warehousing
- Educational ServicesEducational Services
- Health Care & Social AssistanceHealth Care & Social Assistance
- Accommodation & Food ServicesAccommodation & Food Services
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- Finance and InsuranceFinance and Insurance
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- Public AdministrationPublic Administration
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- ConstructionConstruction
- InformationInformation
- MiningMining
- Other Services (except Public Administration)Other Services (except Public Administration)
- Real Estate Rental & LeasingReal Estate Rental & Leasing
- Retail TradeRetail Trade
- UtilitiesUtilities
- Wholesale TradeWholesale Trade