VDB
BDU%3A2020-00948
BDU%3A2020-00948
PUBLISHED
CVSS 9 CRITICAL
Уязвимость почтового сервера Microsoft Exchange Server, связанная с недостатками механизма десериализации, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
9
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft Exchange Server 2019 Cumulative Update 4 | * |
| Microsoft | Microsoft Exchange Server 2019 Cumulative Update 3 | * |
| Microsoft | Microsoft Exchange Server 2013 | Cumulative Update 23 |
| Microsoft | Microsoft Exchange Server 2016 Cumulative Update 14 | * |
| Microsoft | Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 30 | unspecified |
| Microsoft Corp | Microsoft Exchange Server | |
| Microsoft | Microsoft Exchange Server 2016 Cumulative Update 15 | unspecified |
Timeline
- Feb 26, 2020 PoC Published
- Mar 3, 2020 PoC Published
- Mar 5, 2020 PoC Published
- Mar 10, 2020 CVE Published
- Mar 11, 2020 PoC Published
- Sep 16, 2020 PoC Published
- Oct 9, 2020 PoC Published
- Oct 16, 2020 PoC Published
- Oct 20, 2020 PoC Published
- Oct 20, 2020 PoC Published
- Oct 21, 2020 PoC Published
- Oct 22, 2020 PoC Published
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0688 url
- https://nvd.nist.gov/vuln/detail/CVE-2020-0688 url
- http://packetstormsecurity.com/files/156592/Microsoft-Exchange-2019-15.2.221.12-Remote-Code-Execution.html url
- https://www.cisa.gov/sites/default/files/csv/known_exploited_vulnerabilities.csv url
- https://www.zerodayinitiative.com/advisories/ZDI-20-258/ url
- http://packetstormsecurity.com/files/156620/Exchange-Control-Panel-Viewstate-Deserialization.html url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0688 url