attackerkb.com
Multiple Remote Code Execution Vulnerabilities in Microsoft Exchange and Other Systems
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A series of remote code execution (RCE) vulnerabilities have been identified in various systems, notably Microsoft Exchange and Fortra's GoAnywhere MFT. CVE-2020-16875 and CVE-2020-17132 affect Microsoft Exchange, allowing attackers to execute arbitrary code with authenticated user access. CVE-2020-2021 in PAN-OS permits unauthenticated network-based attackers to exploit SAML authentication weaknesses. Additionally, CVE-2023-0669 in GoAnywhere MFT allows pre-authentication command injection, while CVE-2020-28188 in TerraMaster TOS enables RCE via OS command injection. These vulnerabilities have been patched, but active exploitation remains a concern for systems still vulnerable. Security professionals are urged to apply updates and monitor for signs of exploitation.
Key Points: • Microsoft Exchange vulnerabilities allow RCE with authenticated user access. • CVE-2020-2021 enables unauthenticated access to protected resources in PAN-OS. • Fortra's GoAnywhere MFT and TerraMaster TOS also have critical RCE vulnerabilities.