Executive brief
Microsoft Exchange Server contains a remote code execution vulnerability due to improper validation of cmdlet arguments and insecure deserialization of untrusted data. An authenticated attacker can exploit this to execute arbitrary code on the server.
Affected products
- Microsoft Exchange Server 2010 SP3 Rollup 31
Timeline
- 2020-12-09: disclosed: NVD Published Date
- 2020-12-11: patched: Initial patch advisory and analysis by NIST/Microsoft
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild per CISA KEV entry