Enjoyed the US Labor Day weekend? Because it's September 2020 and Exchange Server can be pwned via email

Enjoyed the US Labor Day weekend? Because it's September 2020 and Exchange Server can be pwned via email

A nightmare flaw for Exchange Server headlines this month's Patch Tuesday lineup from Microsoft and others.


September sees a bundle of 129 CVE-listed flaws patched by Microsoft. The vast majority of those, 105 in total, are classified as 'important' risks. Another 23 are considered critical bugs, and one is listed as moderate.


None of the bugs have public exploit code or in-the-wild attacks yet.


Of the nearly two-dozen critical patches, Zero Day Initiative's Dustin Childs says that far and away the most serious is CVE-2020-16875, a memory object error in Exchange Server that allows a poisoned email to execute code with System clearance.


"That doesn’t quite make it wormable, but it’s about the worst-case scenario for Exchange servers," enjoyed labor weekend because september exchange server pwned email