9

CVE-2020-0688

Warnung
Medienbericht
Exploit
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Exchange Server Version 2010 Update sp3_rollup_30
Microsoft ≫ Exchange Server Version 2013 Update cumulative_update_23
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_14
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_15
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_3
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_4

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability

Schwachstelle

Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 99.97% 1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
16.09.2026 18:41
http://packetstormsecurity.com/files/156592/Microsoft-Exchange-2019-15.2.221.12-Remote-Code-Execution.html
Third Party Advisory
Exploit
VDB Entry
http://packetstormsecurity.com/files/156620/Exchange-Control-Panel-Viewstate-Deserialization.html
Third Party Advisory
Exploit
VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0688
Patch
Vendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-258/
Third Party Advisory
VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0688
US Government Resource