Advisory Type |
Vulnerability Intelligence |
Vulnerability Type |
Remote Code Execution |
CVE |
CVE-2020-16875 |
Platform |
Microsoft Exchange Server, On-premise/Cloud |
CVSS |
9.1 |
Impact
- Attackers can execute commands (with the highest privilege) on the target system.
- Corporate email accounts will face the risk of compromise.
- Compromised email accounts can be used in phishing campaigns.
- RCE will give the attackers ability to leave backdoors on the servers.
- Attackers can further the attack deeper into internal networks using the compromised server as a pivot.
Mitigation
- Patch Bypass - Security researchers were able to bypass the patch meant for CVE-2020-16875. The first patch bypass is dubbed CVE-2020-171324. Later a bypass for 171324 was discovered, and now, a final patch is required to address the two other bypasses.