« Volver al listado

CVE-2020-17143

Estado: ModificadaAlta (8.8)—

Microsoft Exchange Server Information Disclosure Vulnerability

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-17143",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secure@microsoft.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "secure@microsoft.com",
      "affectedData": [
        {
          "vendor": "Microsoft",
          "product": "Microsoft Exchange Server 2013 Cumulative Update 23",
          "versions": [
            {
              "status": "affected",
              "version": "15.00.0",
              "lessThan": "publication",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Exchange Server 2016 Cumulative Update 17",
          "versions": [
            {
              "status": "affected",
              "version": "15.01.0",
              "lessThan": "publication",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Exchange Server 2016 Cumulative Update 18",
          "versions": [
            {
              "status": "affected",
              "version": "15.01.0",
              "lessThan": "publication",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Exchange Server 2019 Cumulative Update 6",
          "versions": [
            {
              "status": "affected",
              "version": "15.02.0",
              "lessThan": "publication",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Exchange Server 2019 Cumulative Update 7",
          "versions": [
            {
              "status": "affected",
              "version": "15.02.0",
              "lessThan": "publication",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        }
      ]
    }
  ],
  "published": "2020-12-10T00:15:16.057",
  "references": [
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-17143",
      "source": "secure@microsoft.com"
    },
    {
      "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-17143",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Microsoft Exchange Server Information Disclosure Vulnerability"
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de divulgación de información de Microsoft Exchange"
    }
  ],
  "lastModified": "2026-06-17T02:58:45.790",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DA166F2A-D83B-4D50-AD0B-668D813E0585"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_17:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "079E1E3F-FF25-4B0D-AC98-191D6455A014"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_18:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29805EC7-6403-44B9-91EC-109C087E98EB"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4AB3C25-CEA8-4D66-AEE4-953C8B17911A"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36CE5C6D-9A04-41F5-AE7C-265779833649"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@microsoft.com"
}