MSExchange Control Panel
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| 4 | The Exchange Control Panel web application encountered an unhandled ASP.NET … | Application | N | Y |
Event ID 4: The Exchange Control Panel web application encountered an unhandled ASP.NET exception.
#Description
Error-level Application-log event emitted by Exchange's ECP web component when an unhandled ASP.NET exception occurs while processing a request. During CVE-2020-0688 exploitation the crafted request's targeted ECP page and its __VIEWSTATE payload appear in the event's error text.
Fields #
| Name | Description |
|---|---|
Data | ASP.NET exception text for the failed ECP request: the targeted page path plus the __VIEWSTATEGENERATOR / __VIEWSTATE parameters and the account name when triggered by CVE-2020-0688. |
Community Notes #
Matched by the SigmaHQ 'CVE-2020-0688 Exploitation via Eventlog' rule when the error text carries '&__VIEWSTATE='. Grounding is incident-response prose (TrustedSec, Volexity, BI.ZONE), mutually consistent on Application / Source MSExchange Control Panel / Event ID 4 / Level Error; Microsoft does not publish a numbered reference page for this ASP.NET runtime-error event.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma # view in coverage
T1190