Executive brief
Microsoft Exchange Server fails to properly create unique validation keys at installation time. This vulnerability allows an authenticated remote attacker to execute arbitrary code by sending a specially crafted request to the server, leading to a deserialization flaw.
Affected products
- Microsoft Exchange Server 2010 SP3 Rollup 30
- Microsoft Exchange Server 2013 Cumulative Update 23
- Microsoft Exchange Server 2016 Cumulative Update 14
- Microsoft Exchange Server 2016 Cumulative Update 15
- Microsoft Exchange Server 2019 Cumulative Update 3
- Microsoft Exchange Server 2019 Cumulative Update 4
Timeline
- 2020-02-11: advisory: MSRC advisory published
- 2020-02-13: other: Initial NIST analysis and CVSS scoring completed
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog