← Back to browse · API

CVE-2020-16875

Severity
HIGH
CVSS
8.4
EPSS
0.47145
Risk score
50.1
CISA KEV
No
PoC
No
Published
2020-09-11
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2020-8833, GHSA-5RG4-JQJP-6664
Products
Microsoft:Microsoft Exchange Server 2016 Cumulative Update 16 15.01.0 <publication, Microsoft:Microsoft Exchange Server 2016 Cumulative Update 17 15.01.0 <publication, Microsoft:Microsoft Exchange Server 2019 Cumulative Update 5 15.02.0 <publication, Microsoft:Microsoft Exchange Server 2019 Cumulative Update 6 15.02.0 <publication
Sources
euvd EUVD-2020-8833

Description

<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the vulnerability requires an authenticated user in a certain Exchange role to be compromised.</p> <p>The security update addresses the vulnerability by correcting how Microsoft Exchange handles cmdlet arguments.</p>

References