LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-17144: Microsoft Exchange Server Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-17144 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to perform remote code execution.

CVE-2020-17144 is a remote code execution vulnerability in Microsoft Exchange Server. It stems from improper validation of cmdlet arguments, which can let an attacker run code on the server. Exchange often holds mail, calendars, and directory data, so successful abuse can give an attacker a foothold inside the messaging infrastructure and a path to further movement.

Defenders should treat this as a high-priority issue for any organization running Exchange and confirm exact impact, fixed builds, and deployment steps against the vendor advisory.

How it works

The weakness is classified as CWE-502 (deserialization of untrusted data). In this case, Microsoft Exchange Server improperly validates cmdlet arguments. When those arguments are not checked correctly, an attacker who can supply or influence them may cause the server to process untrusted input in a way that leads to remote code execution.

At a high level, the attacker abuses the flawed validation path so that attacker-controlled data is handled by a privileged Exchange component. The result can be arbitrary code running in the context of the Exchange process. Exact preconditions, authentication requirements, and exploit mechanics are not detailed here; teams must verify those details in the vendor advisory rather than relying on general descriptions of the class.

Am I affected? How to find it in your systems

Microsoft Exchange Server is typically deployed on-premises or in hybrid configurations that still host mailbox or management roles internally. Inventory every server that runs Exchange management tools, mailbox, client access, or related roles.

For signs of exploitation, examine Exchange and Windows security/application logs for unusual cmdlet execution, unexpected process creation under Exchange worker processes, or anomalous PowerShell activity. Specific indicators of compromise are not supplied in the public summary; treat any unexplained administrative or deserialization-related errors as worth investigating and cross-check with vendor and community guidance.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability exactly as described in the vendor advisory. CISA’s required action is to apply updates per vendor instructions; follow that guidance and validate that the expected fixed build is present on every Exchange server afterward.

If you can't patch immediately

Until the vendor update can be installed, reduce the attack surface and increase detection.

These steps lower risk but do not replace the official update. Plan to patch as soon as operationally feasible.

If your data may have been exposed

Actively exploited remote code execution flaws on mail servers can lead to unauthorized access to mailboxes, credentials, or broader domain compromise. Known ransomware use is not documented for this CVE, but any confirmed exploitation should still trigger incident response: isolate affected hosts, preserve logs, reset relevant credentials, and assess mailbox and directory data for unauthorized access. As a simple additional check, users can run a free exposure scan of their email addresses against known breach datasets to see whether those addresses already appear in public breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Exchange Server
WeaknessCWE-502
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities