Junglewise Threat Intelligence

CVE-2020-0688: Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability

CVE-2020-0688 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server fails to properly create unique validation keys at installation time. This vulnerability allows an authenticated remote attacker to execute arbitrary code by sending a specially crafted request to the server, leading to a deserialization flaw.

Affected products

  • Microsoft Exchange Server 2010 SP3 Rollup 30
  • Microsoft Exchange Server 2013 Cumulative Update 23
  • Microsoft Exchange Server 2016 Cumulative Update 14
  • Microsoft Exchange Server 2016 Cumulative Update 15
  • Microsoft Exchange Server 2019 Cumulative Update 3
  • Microsoft Exchange Server 2019 Cumulative Update 4

Timeline

  • 2020-02-11: advisory: MSRC advisory published
  • 2020-02-13: other: Initial NIST analysis and CVSS scoring completed
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats