CERTFR-2020-ALE-007
<strong>\[Mise à jour du 18 mars 2020\]</strong> Des rapports publiés en source ouverte font état d'un faible taux de mise à jour des serveurs *Microsoft Exchange* alors que les codes d'exploitation sont disponibles. Le CERT-FR rappelle qu'il suffit à un attaquant de trouver le compte d'un utilisateur et son mot de passe pour pouvoir compromettre un serveur *Microsoft Exchange* et ensuite obtenir les droits de l'administrateur de domaine *Active Directory* du Système d'Information. <strong>Le CERT-FR recommande l'application du correctif dans les plus brefs délais.</strong> <strong>\[Publication initiale\]</strong> Le CERT-FR a connaissance de campagnes de détection de la vulnérabilité CVE-2020-0688 affectant le serveur Exchange de Microsoft. Une campagne de détection fait partie de la phase de reconnaissance qui est préalable à la phase d'exploitation. Pour rappel, la vulnérabilité CVE-2020-0688 permet une exécution de code arbitraire à distance. Microsoft a publié un correctif de sécurité pour cette vulnérabilité dans le cadre de sa mise à jour mensuelle de février 2020. Si ce n'est déjà fait, le CERT-FR recommande l'application du correctif dans les plus brefs délais.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft Exchange Server 2013 | * |
| Microsoft | Microsoft Exchange Server 2016 Cumulative Update 14 | unspecified |
| Microsoft | Microsoft Exchange Server 2016 Cumulative Update 15 | unspecified |
| Microsoft | Microsoft Exchange Server 2019 Cumulative Update 3 | unspecified |
| Microsoft | Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 30 | unspecified |
| Microsoft | Microsoft Exchange Server 2019 Cumulative Update 4 | unspecified |
Timeline
- Feb 11, 2020 CVE Published
- Mar 3, 2020 PoC Published
- Mar 5, 2020 PoC Published
- Mar 11, 2020 PoC Published
- Sep 16, 2020 PoC Published
- Oct 9, 2020 PoC Published
- Oct 16, 2020 PoC Published
- Oct 20, 2020 PoC Published
- Oct 20, 2020 PoC Published
- Oct 21, 2020 PoC Published
- Oct 22, 2020 PoC Published
- Oct 22, 2020 PoC Published
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0688 url
- https://www.zerodayinitiative.com/advisories/ZDI-20-258/ url
- http://packetstormsecurity.com/files/156592/Microsoft-Exchange-2019-15.2.221.12-Remote-Code-Execution.html url
- http://packetstormsecurity.com/files/156620/Exchange-Control-Panel-Viewstate-Deserialization.html url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0688 url