Microsoft Exchange Server
CVE-2020-17144 — Microsoft Exchange Remote Code Execution Vulnerability
Executive Summary
None
Overview
8.4
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
More Likely
MS Exploit Likelihood
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
High
USER INTERACTION
Required
SCOPE
Changed
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Proof-of-Concept
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 7.6
EPSS Score
0.36514
probability of exploitation in the next 30 days
0.98355 percentile - updated 2026-08-14
View on FIRST.org
Affected Products
1 affected product
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 31 | 4593467 (Security Update) |
Important | Remote Code Execution | Maybe |
Patches
1 patch
| Article | Type | Restart |
|---|---|---|
4593467 |
Security Update | Maybe |
Exploits & PoC
2 public PoCsUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| zcgonvh/CVE-2020-17144 | 158 | 2020-12-09 | weaponized tool for CVE-2020-17144 |
| Airboi/CVE-2020-17144-EXP | 157 | 2020-12-09 | Exchange2010 authorized RCE |
Detection Rules
No public Sigma or Nuclei detection rule has been mapped to this CVE yet. Coverage is concentrated on exploited / high-profile vulnerabilities; check SigmaHQ for updates.
Acknowledgments
zcgonvh from A-TEAM of Legendsec at Qi'anxin Group
References
On This Page