VDB

GSD-2020-0688

GSD-2020-0688 PUBLISHED CVSS 8.800000190734863 HIGH

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.

Risk Scores

CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 14unspecified
MicrosoftMicrosoft Exchange Server 2013Cumulative Update 23
MicrosoftMicrosoft Exchange Server 2010 Service Pack 3 Update Rollup 30unspecified
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 3unspecified
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 4unspecified
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 15unspecified

Timeline

  • Feb 11, 2020 CVE Published
  • Mar 3, 2020 PoC Published
  • Mar 5, 2020 PoC Published
  • Mar 11, 2020 PoC Published
  • Sep 16, 2020 PoC Published
  • Oct 9, 2020 PoC Published
  • Oct 16, 2020 PoC Published
  • Oct 20, 2020 PoC Published
  • Oct 20, 2020 PoC Published
  • Oct 21, 2020 PoC Published
  • Oct 22, 2020 PoC Published
  • Oct 22, 2020 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›