MSExchange Control Panel

Event ID 4: The Exchange Control Panel web application encountered an unhandled ASP.NET exception.

#
Channel
Application

Description

Error-level Application-log event emitted by Exchange's ECP web component when an unhandled ASP.NET exception occurs while processing a request. During CVE-2020-0688 exploitation the crafted request's targeted ECP page and its __VIEWSTATE payload appear in the event's error text.

Fields #

NameDescription
DataASP.NET exception text for the failed ECP request: the targeted page path plus the __VIEWSTATEGENERATOR / __VIEWSTATE parameters and the account name when triggered by CVE-2020-0688.

Community Notes #

Matched by the SigmaHQ 'CVE-2020-0688 Exploitation via Eventlog' rule when the error text carries '&__VIEWSTATE='. Grounding is incident-response prose (TrustedSec, Volexity, BI.ZONE), mutually consistent on Application / Source MSExchange Control Panel / Event ID 4 / Level Error; Microsoft does not publish a numbered reference page for this ASP.NET runtime-error event.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #