A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
Is CVE-2020-0688 exploited?
Listed in the CISA KEV catalog on 2021-11-03.
Federal remediation due 2022-05-03.
Past that date by 1597 days.
Used in ransomware campaigns.
EPSS puts exploitation in the next 30 days at 100.0%.
Public exploit code: packaged in a public tool.
Which products and versions are affected?
Microsoft · Microsoft Exchange Server 2013 · Cumulative Update 23
Microsoft · Microsoft Exchange Server 2019 Cumulative Update 3
Microsoft · Microsoft Exchange Server 2016 Cumulative Update 14
Microsoft · Microsoft Exchange Server 2016 Cumulative Update 15
Microsoft · Microsoft Exchange Server 2019 Cumulative Update 4
Microsoft · Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 30