VDB
GSD-2020-0688
GSD-2020-0688
PUBLISHED
CVSS 8.800000190734863 HIGH
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft Exchange Server 2016 Cumulative Update 14 | unspecified |
| Microsoft | Microsoft Exchange Server 2013 | Cumulative Update 23 |
| Microsoft | Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 30 | unspecified |
| Microsoft | Microsoft Exchange Server 2019 Cumulative Update 3 | unspecified |
| Microsoft | Microsoft Exchange Server 2019 Cumulative Update 4 | unspecified |
| Microsoft | Microsoft Exchange Server 2016 Cumulative Update 15 | unspecified |
Timeline
- Feb 11, 2020 CVE Published
- Mar 3, 2020 PoC Published
- Mar 5, 2020 PoC Published
- Mar 11, 2020 PoC Published
- Sep 16, 2020 PoC Published
- Oct 9, 2020 PoC Published
- Oct 16, 2020 PoC Published
- Oct 20, 2020 PoC Published
- Oct 20, 2020 PoC Published
- Oct 21, 2020 PoC Published
- Oct 22, 2020 PoC Published
- Oct 22, 2020 PoC Published
References
- https://www.zerodayinitiative.com/advisories/ZDI-20-258/ url
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0688 advisory
- http://packetstormsecurity.com/files/156592/Microsoft-Exchange-2019-15.2.221.12-Remote-Code-Execution.html exploit
- http://packetstormsecurity.com/files/156620/Exchange-Control-Panel-Viewstate-Deserialization.html exploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0688 advisory