This content is located here NVD - CVE-2020-0688 (nist.gov)

This Article is set to expire on 2-10-2022 - however, I will likely post a new reason that I did not read or even allow the receipt of your marketing communication.

CVE-2020-0688 Detail

Current Description

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.

View Analysis Description

Severity

   


CVSS 3.x Severity and Metrics:

NIST CVSS score
NIST: NVD
Base Score: 8.8 HIGH
Vector:  CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

NVD Analysts use publicly available information to associate vector strings and CVSS scores. We also display any CVSS information provided within the CVE List from the CNA.
Note: NVD Analysts have published a CVSS score for this CVE based on publicly available information at the time of analysis. The CNA has not provided a score within the CVE List.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other websites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other websites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to This email address is being protected from spambots. You need JavaScript enabled to view it..

Hyperlink Resource
http://packetstormsecurity.com/files/156592/Microsoft-Exchange-2019-15.2.221.12-Remote-Code-Execution.html Exploit  Third Party Advisory  VDB Entry 
http://packetstormsecurity.com/files/156620/Exchange-Control-Panel-Viewstate-Deserialization.html Exploit  Third Party Advisory  VDB Entry 
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0688 Patch  Vendor Advisory 
https://www.zerodayinitiative.com/advisories/ZDI-20-258/ Third Party Advisory  VDB Entry 

Weakness Enumeration

CWE-ID CWE Name Source
CWE-798 Use of Hard-coded Credentials cwe source acceptance level NIST  

Known Affected Software Configurations Switch to CPE 2.2

Configuration 1 ( hide )
  cpe:2.3:a:microsoft:exchange_server:2010:sp3_rollup_30:*:*:*:*:*:*
   Show Matching CPE(s)
  cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_23:*:*:*:*:*:*
   Show Matching CPE(s)
  cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_14:*:*:*:*:*:*
   Show Matching CPE(s)
  cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_15:*:*:*:*:*:*
   Show Matching CPE(s)
  cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_3:*:*:*:*:*:*
   Show Matching CPE(s)
  cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_4:*:*:*:*:*:*
   Show Matching CPE(s)

 Denotes Vulnerable Software

Main Menu