Cloud Defense Logo

Products

Solutions

Company

Book A Live Demo

CVE-2020-17143 : Security Advisory and Response

Learn about CVE-2020-17143, an Information Disclosure vulnerability in Microsoft Exchange Server affecting various versions. Find out the impact, affected systems, exploitation mechanism, and mitigation steps.

Microsoft Exchange Server Information Disclosure Vulnerability was published on December 8, 2020. It affects various versions of Microsoft Exchange Server.

Understanding CVE-2020-17143

This CVE involves an Information Disclosure vulnerability in Microsoft Exchange Server.

What is CVE-2020-17143?

The CVE-2020-17143 is an Information Disclosure vulnerability in Microsoft Exchange Server, allowing unauthorized access to sensitive information.

The Impact of CVE-2020-17143

This vulnerability has a base severity of HIGH with a CVSS base score of 8.8. It can lead to unauthorized disclosure of sensitive data, potentially compromising the confidentiality and integrity of the affected systems.

Technical Details of CVE-2020-17143

This section provides more technical insights into the vulnerability.

Vulnerability Description

The vulnerability allows attackers to access sensitive information on affected Microsoft Exchange Server versions.

Affected Systems and Versions

        Microsoft Exchange Server 2019 Cumulative Update 6 (Version 15.02.0)
        Microsoft Exchange Server 2016 Cumulative Update 17 (Version 15.01.0)
        Microsoft Exchange Server 2019 Cumulative Update 7 (Version 15.02.0)
        Microsoft Exchange Server 2016 Cumulative Update 18 (Version 15.01.0)
        Microsoft Exchange Server 2013 Cumulative Update 23 (Version 15.00.0)

Exploitation Mechanism

The vulnerability can be exploited by attackers to gain unauthorized access to sensitive information stored on the affected Microsoft Exchange Server instances.

Mitigation and Prevention

To address CVE-2020-17143, follow these mitigation and prevention measures.

Immediate Steps to Take

        Apply security updates provided by Microsoft for the affected Exchange Server versions.
        Monitor for any unauthorized access or unusual activities on the Exchange Server.

Long-Term Security Practices

        Regularly update and patch Microsoft Exchange Server to prevent known vulnerabilities.
        Implement access controls and monitoring mechanisms to detect and prevent unauthorized access.

Patching and Updates

Ensure timely installation of security patches and updates released by Microsoft for Exchange Server to mitigate the risk of exploitation.

Popular CVEs

CVE Id

Published Date

Is your System Free of Underlying Vulnerabilities?
Find Out Now