A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
CVE-2020-0688 viene sfruttato?
Inserito nel catalogo CISA KEV il 2021-11-03.
Scadenza di remediation federale: 2022-05-03.
Oltre quella data da 1597 giorni.
Usato in campagne ransomware.
EPSS stima la probabilità di sfruttamento nei prossimi 30 giorni al 100.0%.
Codice di exploit pubblico: integrato in uno strumento pubblico.
Quali prodotti e versioni sono interessati?
Microsoft · Microsoft Exchange Server 2013 · Cumulative Update 23
Microsoft · Microsoft Exchange Server 2019 Cumulative Update 3
Microsoft · Microsoft Exchange Server 2016 Cumulative Update 14
Microsoft · Microsoft Exchange Server 2016 Cumulative Update 15
Microsoft · Microsoft Exchange Server 2019 Cumulative Update 4
Microsoft · Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 30